CVE-2026-105145
Received Received - Intake

Information Disclosure in Weaviate Verba

Vulnerability report for CVE-2026-105145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpoint. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
semitechnologies verba to 2.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Weaviate Verba versions up to 2.1.3. It allows a remote attacker to exfiltrate LLM and parser API keys from the server's environment by exploiting an unauthenticated WebSocket endpoint (/ws/generate_stream). The attacker sends a malicious RAG generator configuration with a custom OpenAI-compatible URL but omits the API Key field, causing Verba to read the real key from the environment and send it to the attacker-controlled URL.

Detection Guidance

Monitor network traffic for outbound requests to unexpected or attacker-controlled URLs from the /ws/generate_stream WebSocket endpoint. Check logs for unauthorized access attempts or unusual API key transmissions. Inspect environment variables for exposed keys like OPENAI_API_KEY or similar.

Impact Analysis

The vulnerability can lead to unauthorized access to your LLM provider resources, potential billing abuse, and exposure of sensitive API keys like OPENAI_API_KEY, OPENAI_EMBED_API_KEY, UPSTAGE_API_KEY, UNSTRUCTURED_API_KEY, and EMBEDDING_SERVICE_KEY. Attackers can use these keys to make unauthorized API calls, incurring costs or accessing private data.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive API keys and environment variables, which may include credentials for LLM services. Such a breach could violate GDPR if personal data is exposed or HIPAA if protected health information is involved, due to insufficient access controls and lack of encryption for transmitted secrets.

Mitigation Strategies

Immediately restrict access to the /ws/generate_stream endpoint by binding Verba to localhost or a trusted network interface. Block outbound traffic to untrusted domains. Rotate all exposed API keys (OPENAI_API_KEY, OPENAI_EMBED_API_KEY, etc.) and disable the WebSocket endpoint if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart