Skip to content
seaweedfsGHSA-q97m-8853-pq76

SeaweedFS Vulnerable to SQL Injection

Medium6.5CVE-2024-40120 · Published May 16, 2025 · updated Sep 10, 2026

seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/seaweedfs/seaweedfs
Go
< 0.0.0-20240625155419-9ac1023362000.0.0-20240625155419-9ac102336200
Details and references

More seaweedfs advisories

All seaweedfs
Advisory
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
High8.1Sep 2
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
Critical9.8Sep 2
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
High7.7Aug 28
seaweedfs: improper authorization
Medium4.3Aug 28
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
HighAug 12
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Critical9.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.