Skip to content
WeaviateGHSA-hmmh-292h-3364

Weaviate OSS has path traversal vulnerability via the Shard Movement API

HighCVE-2025-67819 · Published Dec 12, 2025 · updated Dec 18, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/weaviate/weaviate
Go
>= 1.30.0, < 1.30.201.30.20
>= 1.31.0-rc.0, < 1.31.191.31.19
>= 1.32.0-rc.0, < 1.32.161.32.16
>= 1.33.0-rc.0, < 1.33.41.33.4
Details and references

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2025-67819, GO-2025-4238

More Weaviate advisories

All Weaviate
DateAdvisory
Dec 122025Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
CVE-2025-67818Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4
Jun 8Weaviate has an Improper Authorization issue
CVE-2026-11500Low5.0fixed in 1.38.0-rc.0
Aug 222023Weaviate denial of service vulnerability
CVE-2023-38976High7.5fixed in 1.18.6, 1.19.13, 1.20.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.