WeaviateGHSA-hmmh-292h-3364
Weaviate OSS has path traversal vulnerability via the Shard Movement API
HighCVE-2025-67819 · Published Dec 12, 2025 · updated Dec 18, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/weaviate/weaviate Go | >= 1.30.0, < 1.30.20 | 1.30.20 |
| >= 1.31.0-rc.0, < 1.31.19 | 1.31.19 | |
| >= 1.32.0-rc.0, < 1.32.16 | 1.32.16 | |
| >= 1.33.0-rc.0, < 1.33.4 | 1.33.4 |
Details and references
An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2025-67819, GO-2025-4238
- nvd.nist.gov/vuln/detail/CVE-2025-67819
- github.com/weaviate/weaviate/commit/4ff2cc89277c264c37d0f7316d9eb6368cfc30ff
- github.com/weaviate/weaviate/commit/89c2270869e6d64f5b5276b8626c11cd816c6665
- github.com/weaviate/weaviate/commit/b18cc7ea82d80a61e7943361a6e335e3fd5a49c7
- github.com/advisories/GHSA-hmmh-292h-3364
- github.com/weaviate/weaviate
- weaviate.io/blog/weaviate-security-release-november-2025
More Weaviate advisories
All Weaviate| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 122025 | Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip CVE-2025-67818Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4 | High | 1.30.20, 1.31.19, 1.32.16, 1.33.4 |
| Jun 8 | Weaviate has an Improper Authorization issue CVE-2026-11500Low5.0fixed in 1.38.0-rc.0 | Low5.0 | 1.38.0-rc.0 |
| Aug 222023 | Weaviate denial of service vulnerability CVE-2023-38976High7.5fixed in 1.18.6, 1.19.13, 1.20.6 | High7.5 | 1.18.6, 1.19.13, 1.20.6 |