GHSA-7v39-2hx7-7c43

Suggest an improvement
Source
https://github.com/advisories/GHSA-7v39-2hx7-7c43
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-7v39-2hx7-7c43/GHSA-7v39-2hx7-7c43.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7v39-2hx7-7c43
Aliases
Downstream
Published
2025-12-12T18:30:35Z
Modified
2025-12-15T20:56:03.599764Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
Details

An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2025-12-12T17:15:45Z",
    "github_reviewed_at": "2025-12-12T20:25:25Z",
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-22",
        "CWE-61"
    ]
}
References

Affected packages

Go

github.com/weaviate/weaviate

Package

Name
github.com/weaviate/weaviate
View open source insights on deps.dev
Purl
pkg:golang/github.com/weaviate/weaviate

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.30.20

github.com/weaviate/weaviate

Package

Name
github.com/weaviate/weaviate
View open source insights on deps.dev
Purl
pkg:golang/github.com/weaviate/weaviate

Affected ranges

Type
SEMVER
Events
Introduced
1.31.0-rc.0
Fixed
1.31.19

github.com/weaviate/weaviate

Package

Name
github.com/weaviate/weaviate
View open source insights on deps.dev
Purl
pkg:golang/github.com/weaviate/weaviate

Affected ranges

Type
SEMVER
Events
Introduced
1.32.0-rc.0
Fixed
1.32.16

github.com/weaviate/weaviate

Package

Name
github.com/weaviate/weaviate
View open source insights on deps.dev
Purl
pkg:golang/github.com/weaviate/weaviate

Affected ranges

Type
SEMVER
Events
Introduced
1.33.0-rc.0
Fixed
1.33.4