CVE-2025-67818
EUVD-2025-20309412.12.2025, 17:15
An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| weaviate | weaviate | 𝑥 < 1.33.4 |
𝑥
= Vulnerable software versions