VDB

CVE-2025-67819

CVE-2025-67819 PUBLISHED CVSS 8.699999809265137 HIGH

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.

EPSS 0.49% · 40.2th percentile

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.49%
40.2th percentile

Affected Products

VendorProductVersions
weaviateweaviate1.30.0, 1.33.0, 1.32.0
n/an/an/a
github.comweaviate/weaviate1.33.0-rc.0, 1.32.0-rc.0, 1.31.0-rc.0

Timeline

  • Dec 12, 2025 CVE ID Reserved
  • Dec 12, 2025 CVE Published
  • Dec 12, 2025 CVE Updated
  • Dec 12, 2025 PoC Published
  • Dec 13, 2025 EPSS Score
  • Dec 17, 2025 EPSS Score
  • Dec 21, 2025 EPSS Score
  • Dec 26, 2025 EPSS Score
  • Dec 30, 2025 EPSS Score
  • Jan 3, 2026 EPSS Score
  • Jan 7, 2026 EPSS Score
  • Jan 11, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›