PT-2025-50957 · Unknown · Weaviate Oss

·

CVE-2025-67818

·

Published

2025-12-12

·

Updated

2026-07-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Weaviate OSS versions prior to 1.33.4
Description An attacker who can insert data into the database can create an entry name containing an absolute path (for example, /etc/...) or utilize parent directory traversal (../../..) to bypass the restore root during a backup restoration. This could lead to the creation or overwriting of files in arbitrary locations within the application's permissions.
Recommendations Update to version 1.33.4 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67818
GHSA-7V39-2HX7-7C43
GO-2025-4237
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0037-1

Affected Products

Weaviate Oss