Skip to main content
WeaviateCybersecurity incident

A security audit of popular AI tools found that Weaviate's default Helm chart enables anonymous read and write access, leaving vector data and ingested documents unsecured within a Kubernetes cluster.

What happened

Post: "We audited the default Helm charts and Docker configs of popular AI stack tools (Ray, Weaviate, MCP servers, LangChain). The out-of-the-box security..."

Source

Post

Highlighted: the lines this signal was extracted from

Over the past few weeks, we set up a fresh cluster to test what actually gets deployed when an engineer runs helm install with zero extra configuration on popular AI, vector DB, and MCP charts (Ray, vLLM, LiteLLM, Qdrant, Weaviate, KubeRay, etc.). Everyone focuses on prompt injection and model jailbreaks, but the platform-level defaults on these workloads look like Kubernetes five to seven years ago: Ray / KubeRay (Distributed Compute) The default deployment accepts unauthenticated job submissions over internal cluster networking. Worker containers run with passwordless sudo out of the box. Any compromised pod on the flat cluster network that can reach the Ray API gets arbitrary remote execution as root with zero barrier. MCP (Model Context Protocol) Servers Several popular MCP server implementations implement local protection solely by checking Host: localhost. Any basic SSRF or internal proxy passing -H "Host: localhost" bypasses this immediately. In live testing, one Kubernetes MCP server mounted a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed over unauthenticated HTTP. LiteLLM Migration Job Credential Leak The primary deployment pulls the database password from a Secret using secretKeyRef, but the database migration Job embeds the raw database password in plain-text environment variables. Anyone with basic cluster read...

Keep reading with a free account

The rest of this post, and every signal for Weaviate, is in your free account.

Also quoted as evidence

  • Multiple upstream charts still ship with default values that enable anonymous read and write access.

    From the post

  • Raw embeddings and ingested document payloads are queryable by any internal service without an authentication header.

    From the post

Comments on the post

5 of 12 comments
  • “Great work, I bet the projects will be grateful for the issues you e raised in their repo. Maybe you could even make some branches to fix the bigger issues you've found.”

    u/totheendandbackagain4 points · Sep 27, 2026View

  • “Default NetworkPolicies and dropping service-account tokens are good baselines, but I’d also gate rendered manifests in CI, including operator-generated CRD paths, since static scanners often miss resources materialized later.”

    u/Torutofu_Raeva3 points · Sep 27, 2026View

  • “No surprise there, far too many people assume AI means secure, it is the opposite.”

    u/dariusbiggs1 points · Sep 28, 2026View

  • “It’s because people are rushing this stuff to market to try and get ahead of the competition”

    u/raisputin1 points · Sep 28, 2026View

  • “not surprising, helm rewards quick and easy demo setups not long term day-2 ops, that gets quickly dependent on the actual integration into the platform it needs to land and a yaml DSL translated through a text engine (nindent all over), is a recipe for hard to maintain and easy to break setups helm is great for demos, but most teams have a sunken cost fallacy issue before they invest into a p”

    u/vincentdesmet1 points · Sep 28, 2026View

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/devops
Stage
Confirmed
Event date
Sep 2026

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Completed
Category
Vulnerability disclosed
Virality
Somewhat high
Post kind
Text
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • security
  • kubernetes
  • vulnerability
  • helm
  • ai

Extraction

Sentiment
Negative
Detected
Sep 27, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for Weaviate and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Weaviate this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/58351b13-210d-5af4-a9d5-09f1c8415706 returns this record as JSON. POST /v1/companies/enrich returns every signal for weaviate.io.

{
  "signal_id": "58351b13-210d-5af4-a9d5-09f1c8415706",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-09-27T13:44:24+00:00",
  "company": {
    "name": "Weaviate",
    "domain": "weaviate.io"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "security",
      "kubernetes",
      "helm",
      "ai",
      "vulnerability"
    ],
    "post_id": "1wrkllb",
    "summary": "A security audit of popular AI tools found that Weaviate's default Helm chart enables anonymous read and write access, leaving vector data and ingested documents unsecured within a Kubernetes cluster.",
    "category": "vulnerability_disclosed",
    "comments": [
      {
        "url": "https://www.reddit.com/r/devops/comments/1wrkllb/comment/pcdg5p6/",
        "depth": 0,
        "score": 4,
        "author": "totheendandbackagain",
        "excerpt": "Great work, I bet the projects will be grateful for the issues you e raised in their repo. Maybe you could even make some branches to fix the bigger issues you've found.",
        "posted_at": "2026-09-27T14:32:20.000Z",
        "author_url": "https://www.reddit.com/user/totheendandbackagain/"
      },
      {
        "url": "https://www.reddit.com/r/devops/comments/1wrkllb/comment/pcdmqvh/",
        "depth": 0,
        "score": 3,
        "author": "Torutofu_Raeva",
        "excerpt": "Default NetworkPolicies and dropping service-account tokens are good baselines, but I’d also gate rendered manifests in CI, including operator-generated CRD paths, since static scanners often miss resources materialized later.",
        "posted_at": "2026-09-27T15:02:28.000Z",
        "author_url": "https://www.reddit.com/user/Torutofu_Raeva/"
      },
      {
        "url": "https://www.reddit.com/r/devops/comments/1wrkllb/comment/pchhuvq/",
        "depth": 0,
        "score": 1,
        "author": "dariusbiggs",
        "excerpt": "No surprise there, far too many people assume AI means secure, it is the opposite.",
        "posted_at": "2026-09-28T01:01:46.000Z",
        "author_url": "https://www.reddit.com/user/dariusbiggs/"
      },
      {
        "url": "https://www.reddit.com/r/devops/comments/1wrkllb/comment/pchlaeu/",
        "depth": 0,
        "score": 1,
        "author": "raisputin",
        "excerpt": "It’s because people are rushing this stuff to market to try and get ahead of the competition",
        "posted_at": "2026-09-28T01:20:00.000Z",
        "author_url": "https://www.reddit.com/user/raisputin/"
      },
      {
        "url": "https://www.reddit.com/r/devops/comments/1wrkllb/comment/pchpno9/",
        "depth": 0,
        "score": 1,
        "author": "vincentdesmet",
        "excerpt": "not surprising, helm rewards quick and easy demo setups\nnot long term day-2 ops, that gets quickly dependent on the actual integration into the platform it needs to land\n\n and a yaml DSL translated through a text engine (nindent all over), is a recipe for hard to maintain and easy to break setups\n\n helm is great for demos, but most teams have a sunken cost fallacy issue before they invest into a p",
        "posted_at": "2026-09-28T01:43:30.000Z",
        "author_url": "https://www.reddit.com/user/vincentdesmet/"
      }
    ],
    "evidence": [
      "[post] we set up a fresh cluster to test what actually gets deployed when an engineer runs helm install with zero extra configuration on popular AI, vector DB, and MCP charts (Ray, vLLM, LiteLLM, Qdrant, Weaviate, KubeRay, etc.).",
      "[post] Multiple upstream charts still ship with default values that enable anonymous read and write access.",
      "[post] Raw embeddings and ingested document payloads are queryable by any internal service without an authentication header."
    ],
    "virality": "somewhat_high",
    "post_date": "2026-09-27T13:44:24.000Z",
    "post_kind": "text",
    "post_text": "Over the past few weeks, we set up a fresh cluster to test what actually gets deployed when an engineer runs helm install with zero extra configuration on popular AI, vector DB, and MCP charts (Ray, vLLM, LiteLLM, Qdrant, Weaviate, KubeRay, etc.).\n\nEveryone focuses on prompt injection and model jailbreaks, but the platform-level defaults on these workloads look like Kubernetes five to seven years ago:\n\nRay / KubeRay (Distributed Compute)\n\nThe default deployment accepts unauthenticated job submissions over internal cluster networking.\n\nWorker containers run with passwordless sudo out of the box.\n\nAny compromised pod on the flat cluster network that can reach the Ray API gets arbitrary remote execution as root with zero barrier.\n\nMCP (Model Context Protocol) Servers\n\nSeveral popular MCP server implementations implement local protection solely by checking Host: localhost.\n\nAny basic SSRF or internal proxy passing -H \"Host: localhost\" bypasses this immediately.\n\nIn live testing, one Kubernetes MCP server mounted a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed over unauthenticated HTTP.\n\nLiteLLM Migration Job Credential Leak\n\nThe primary deployment pulls the database password from a Secret using secretKeyRef, but the database migration Job embeds the raw database password in plain-text environment variables.\n\nAnyone with basic cluster read permissions...",
    "sentiment": "negative",
    "subreddit": "devops",
    "event_date": "2026-09",
    "post_flair": [
      "Security"
    ],
    "post_title": "We audited the default Helm charts and Docker configs of popular AI stack tools (Ray, Weaviate, MCP servers, LangChain). The out-of-the-box security defaults are surprisingly bad.",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/devops/comments/1wrkllb/we_audited_the_default_helm_charts_and_docker/",
    "entity_role": "subject",
    "post_author": "No-Peanut-6988",
    "upvote_ratio": 0.9565217391304348,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/devops/",
    "total_upvotes": 21,
    "comments_total": 12,
    "total_comments": 12,
    "event_date_text": "Over the past few weeks",
    "post_author_url": "https://www.reddit.com/user/No-Peanut-6988/",
    "signal_category": "event",
    "comments_included": 5
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.