CVE-2025-67818
Last modified
CVE-2025-67818 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Weaviate | Weaviate | < 1.33.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67818?
How severe is CVE-2025-67818?
How do I fix CVE-2025-67818?
Are you affected by CVE-2025-67818?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
