← Back

CVE-2025-67819

nvd nist
Published: Dec 12, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.

Affected (4)

Products: Weaviate: Weaviate
1 product
Weaviate
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Weaviate
From 1.30.0 to 1.30.19
From 1.31.0 to 1.31.18
From 1.32.0 to 1.32.15
From 1.33.0 to 1.33.3

References (2)

Timeline

No history available yet.