Skip to main content
WeaviateLaunch

Weaviate security release - Medium and High severity fixes for CVEs

What happened

Weaviate launched security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x on Nov 7th '25.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Weaviate security release - medium and high severity fixes for CVEs. This week Weaviate has released security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x. These patches contain a fix for two pending CVEs (Weaviate will update this blog once Weaviate has had CVEs reserved), a high severity path traversal vulnerability in its backup modules, and a medium severity path traversal vulnerability in its shard movement module. As per its security policy, Weaviate customers running in Weaviate Cloud, and Marketplace customers on AWS, Azure and GCP have been patched seamlessly. Its Weaviate Enterprise Support customers have received early notification under embargo. Path traversal via backup zipslip (CVE pending). An attacker with access to create objects in Weaviate can use symbolic links, absolute paths or "..." segments to escape the intended restore root for backups, and create or overwrite files at arbitrary paths within Weaviate's privilege scope. The CVSS score for this vulnerability is High (7.2) Impacted versions of Weaviate are <= Weaviate 1.30.19, <= Weaviate 1.31.18, <= Weaviate 1.32.15 and <= Weaviate 1.33.3. Weaviate recommend that impacted customers update their Weaviate installations to fully address the vulnerability. The Backup modules can also be disabled by removing any backup* entries from the "enabled_modules" flag. Path traversal via Shard...

Keep reading with a free account

The rest of this article, and every signal for Weaviate, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Takes effect
Nov 7, 2025

The full record

From the Signal API record

Details

Product
security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x
Category
Launches

Topics and mentions

Product tags

  • security

Extraction

Confidence
96%
Detected
Nov 7, 2025
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Weaviate and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Weaviate this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/a9d485ff-3f02-4cb5-94c5-fe1d5f1920a1 returns this record as JSON. POST /v1/companies/enrich returns every signal for weaviate.io.

{
  "signal_id": "a9d485ff-3f02-4cb5-94c5-fe1d5f1920a1",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2025-11-07T00:00:00+00:00",
  "company": {
    "name": "Weaviate",
    "domain": "weaviate.io"
  },
  "data": {
    "url": "https://weaviate.io/blog/weaviate-security-release-november-2025",
    "title": "Weaviate security release - Medium and High severity fixes for CVEs",
    "excerpt": "Weaviate security release - medium and high severity fixes for CVEs.\n\nThis week Weaviate has released security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x. These patches contain a fix for two pending CVEs (Weaviate will update this blog once Weaviate has had CVEs reserved), a high severity path traversal vulnerability in its backup modules, and a medium severity path traversal vulnerability in its shard movement module.\n\nAs per its security policy, Weaviate customers running in Weaviate Cloud, and Marketplace customers on AWS, Azure and GCP have been patched seamlessly. Its Weaviate Enterprise Support customers have received early notification under embargo.\n\nPath traversal via backup zipslip (CVE pending).\n\nAn attacker with access to create objects in Weaviate can use symbolic links, absolute paths or \"...\" segments to escape the intended restore root for backups, and create or overwrite files at arbitrary paths within Weaviate's privilege scope.\n\nThe CVSS score for this vulnerability is High (7.2)\n\nImpacted versions of Weaviate are <= Weaviate 1.30.19, <= Weaviate 1.31.18, <= Weaviate 1.32.15 and <= Weaviate 1.33.3. Weaviate recommend that impacted customers update their Weaviate installations to fully address the vulnerability. The Backup modules can also be disabled by removing any backup* entries from the \"enabled_modules\" flag.\n\nPath traversal via Shard...",
    "product": "security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x",
    "summary": "Weaviate launched security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x on Nov 7th '25.",
    "category": "launches",
    "found_at": "2025-11-07T00:00:00Z",
    "planning": false,
    "image_url": "https://weaviate.io/assets/images/hero-26912f425452f1718b0dc5e3761ff479.png",
    "confidence": 0.9632,
    "product_data": {
      "full_text": "security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x",
      "fuzzy_match": true
    },
    "product_tags": [
      "security"
    ],
    "published_at": "2025-11-07T00:00:00Z",
    "effective_date": "2025-11-07",
    "article_sentence": "This week Weaviate has released security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.