Skip to content
WeaviateGHSA-7v39-2hx7-7c43

Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip

HighCVE-2025-67818 · Published Dec 12, 2025 · updated Dec 18, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/weaviate/weaviate
Go
< 1.30.201.30.20
>= 1.31.0-rc.0, < 1.31.191.31.19
>= 1.32.0-rc.0, < 1.32.161.32.16
>= 1.33.0-rc.0, < 1.33.41.33.4
Details and references

An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22, CWE-61
Also known as
CVE-2025-67818, GO-2025-4237

More Weaviate advisories

All Weaviate
DateAdvisory
Dec 122025Weaviate OSS has path traversal vulnerability via the Shard Movement API
CVE-2025-67819Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4
Jun 8Weaviate has an Improper Authorization issue
CVE-2026-11500Low5.0fixed in 1.38.0-rc.0
Aug 222023Weaviate denial of service vulnerability
CVE-2023-38976High7.5fixed in 1.18.6, 1.19.13, 1.20.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.