CVE-2025-67818

HIGH

Weaviate < 1.33.4 - Path Traversal and Arbitrary File Write via Backup Restore

Title source: llm
STIX 2.1

Description

An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.

Scores

CVSS v3 7.2
EPSS 0.0066
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
weaviate/weaviate < 1.33.4
weaviate/weaviate 0 - 1.30.20Go
Published Dec 12, 2025
Tracked Since Feb 18, 2026