GHSA-7v39-2hx7-7c43 · Severity: high · Ecosystem: go — Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.
Conclusion & alert: CVE-2025-67818 is rated Moderate Risk (45.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.66%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.25% | 0.66% | +0.42% |
| 2 | 2026-05-10 | 0.35% | 0.25% | -0.11% |
| 3 | 2026-04-13 | — | 0.35% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-7v39-2hx7-7c43 · Severity: high · Ecosystem: go — Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
| URL | Tags |
|---|---|
| https://github.com/weaviate/weaviate | Product |
| https://weaviate.io/blog/weaviate-security-release-november-2025 | Vendor Advisory |