PT-2025-50958 · Weaviate · Weaviate Oss

CVE-2025-67819

·

Publicado

2025-12-12

·

Atualizado

2026-07-30

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Weaviate OSS versions prior to 1.33.4
Description A flaw exists in Weaviate OSS that allows an attacker to read arbitrary files accessible to the service process. This occurs because of insufficient validation of the fileName field during file transfer operations. Specifically, an attacker who can call the GetFile method while a shard is paused and the FileReplicationService is reachable can exploit this issue.
Recommendations Update Weaviate OSS to version 1.33.4 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67819
GHSA-HMMH-292H-3364
GO-2025-4238
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0037-1

Produtos afetados

Weaviate Oss