seaweedfsGHSA-q97m-8853-pq76
SeaweedFS Vulnerable to SQL Injection
Medium6.5CVE-2024-40120 · Published May 16, 2025 · updated Sep 10, 2026
seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/seaweedfs/seaweedfs Go | < 0.0.0-20240625155419-9ac102336200 | 0.0.0-20240625155419-9ac102336200 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- BIT-seaweedfs-2024-40120, CVE-2024-40120, GO-2025-3690
More seaweedfs advisories
All seaweedfs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths | High8.1 | 0.0.0-20260512171048-05ed5c9ae8a2 |
| Sep 2 | SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control | Critical9.8 | 0.0.0-20260512171108-5e8f99f40a8a |
| Aug 28 | SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read | High7.7 | 0.0.0-20260612000715-b44cf51fe931 |
| Aug 28 | seaweedfs: improper authorization | Medium4.3 | 0.0.0-20260614205536-b13463880c1f |
| Aug 12 | SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access | High | 0.0.0-20260526080459-dd1b4287899e |
| Aug 11 | SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle | Critical9.3 | 0.0.0-20260512171120-69da20bdaec9 |