{"id":"CVE-2024-7340","aliases":["GHSA-r49h-6qxq-624f","PYSEC-2026-2035"],"title":"Weave server API vulnerable to arbitrary file leak","summary":"Weave server API vulnerable to arbitrary file leak","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"weave","product":"weave","ecosystem":"pip","affected":["weave < 0.50.8"],"patched":["weave 0.50.8"],"published":"2024-07-31","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-r49h-6qxq-624f","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7340"},{"url":"https://github.com/wandb/weave/pull/1657"},{"url":"https://github.com/wandb/weave/commit/f43d5fb75e0d52933a52ecd9a0ce2f9b082e6c9f"},{"url":"https://github.com/wandb/weave"},{"url":"https://research.jfrog.com/vulnerabilities/wandb-weave-server-remote-arbitrary-file-leak-jfsa-2024-001039248"}],"tags":["osv","pip","exploit-available"],"epss":0.05015,"epssPercentile":0.91913,"ingestedAt":"2026-07-08T18:25:52.641Z","exploits":{"nuclei":["CVE-2024-7340"],"checkedAt":"2026-09-21T15:26:51.520Z"},"exploitAvailable":true,"slug":"CVE-2024-7340","body":"## Overview\n\nThe Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.\n\n## Affected packages\n\n- `weave < 0.50.8`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `weave 0.50.8`","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":1,"exploitation":12,"ransomware":0},"changes":[{"seq":4750,"id":"CVE-2024-7340","ts":1788887203540,"field":"exploit_available","old":"false","new":"true"},{"seq":3633,"id":"CVE-2024-7340","ts":1788886319717,"field":"exploit_available","old":"true","new":"false"},{"seq":2484,"id":"CVE-2024-7340","ts":1788882988241,"field":"exploit_available","old":"false","new":"true"},{"seq":1513,"id":"CVE-2024-7340","ts":1788882401826,"field":"exploit_available","old":"true","new":"false"},{"seq":627,"id":"CVE-2024-7340","ts":1788881839542,"field":"exploit_available","old":"false","new":"true"}]}