icon

We found results for “

CVE-2025-67819

Good to know:

icon
icon

Date: December 12, 2025

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-22

Top Fix

icon

Upgrade Version

Upgrade to version github.com/weaviate/weaviate - v1.30.20;github.com/weaviate/weaviate - v1.31.19;github.com/weaviate/weaviate - v1.32.16;github.com/weaviate/weaviate - v1.33.4;https://github.com/weaviate/weaviate.git - v1.30.20;https://github.com/weaviate/weaviate.git - v1.31.19;https://github.com/weaviate/weaviate.git - v1.32.16;https://github.com/weaviate/weaviate.git - v1.33.4

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us