We found results for “”
CVE-2025-67819
Good to know:
Date: December 12, 2025
An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22Top Fix
Upgrade Version
Upgrade to version github.com/weaviate/weaviate - v1.30.20;github.com/weaviate/weaviate - v1.31.19;github.com/weaviate/weaviate - v1.32.16;github.com/weaviate/weaviate - v1.33.4;https://github.com/weaviate/weaviate.git - v1.30.20;https://github.com/weaviate/weaviate.git - v1.31.19;https://github.com/weaviate/weaviate.git - v1.32.16;https://github.com/weaviate/weaviate.git - v1.33.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


