WeaviateGHSA-7v39-2hx7-7c43
Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
HighCVE-2025-67818 · Published Dec 12, 2025 · updated Dec 18, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/weaviate/weaviate Go | < 1.30.20 | 1.30.20 |
| >= 1.31.0-rc.0, < 1.31.19 | 1.31.19 | |
| >= 1.32.0-rc.0, < 1.32.16 | 1.32.16 | |
| >= 1.33.0-rc.0, < 1.33.4 | 1.33.4 |
Details and references
An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22, CWE-61
- Also known as
- CVE-2025-67818, GO-2025-4237
- nvd.nist.gov/vuln/detail/CVE-2025-67818
- github.com/weaviate/weaviate/commit/169df2dc92bc232df62e8fab0a20db2e5371f7aa
- github.com/weaviate/weaviate/commit/89c2270869e6d64f5b5276b8626c11cd816c6665
- github.com/advisories/GHSA-7v39-2hx7-7c43
- github.com/weaviate/weaviate
- weaviate.io/blog/weaviate-security-release-november-2025
More Weaviate advisories
All Weaviate| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 122025 | Weaviate OSS has path traversal vulnerability via the Shard Movement API CVE-2025-67819Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4 | High | 1.30.20, 1.31.19, 1.32.16, 1.33.4 |
| Jun 8 | Weaviate has an Improper Authorization issue CVE-2026-11500Low5.0fixed in 1.38.0-rc.0 | Low5.0 | 1.38.0-rc.0 |
| Aug 222023 | Weaviate denial of service vulnerability CVE-2023-38976High7.5fixed in 1.18.6, 1.19.13, 1.20.6 | High7.5 | 1.18.6, 1.19.13, 1.20.6 |