Description
A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpoint. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Data exposure via environment information disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the get_environment function in the generate_stream endpoint of Weaviate Verba, allowing remote attackers to retrieve environment information that should remain confidential; this flaw reflects weaknesses in CWE-200 (Information Exposure) and CWE-284 (Improper Authorization) and could enable an attacker to access configuration details or other sensitive data.

Affected Systems

This issue affects installations of Weaviate Verba version 2.1.3 or earlier; the vulnerable code resides in goldenverba/components/util.py within the generate_stream endpoint.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity impact, and no EPSS score is available, although publicly disclosed exploits are known; the vulnerability is not listed in CISA's KEV catalog, but the attack vector is remote, meaning an attacker can attempt exploitation from any network location that can reach the generate_stream API.

Generated by OpenCVE AI on October 4, 2026 at 12:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Weaviate Verba to the latest release that includes the fix for the get_environment information disclosure (e.g., v2.1.4 or higher).
  • If an immediate upgrade is impractical, restrict access to the generate_stream endpoint by enforcing authentication or limiting traffic to a trusted network segment via firewall or security group rules.
  • As a temporary defensive measure, disable or remove the generate_stream feature until a patched version is deployed.

Generated by OpenCVE AI on October 4, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpoint. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Weaviate Verba generate_stream Endpoint util.py get_environment information disclosure
First Time appeared Weaviate
Weaviate verba
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:weaviate:verba:*:*:*:*:*:*:*:*
Vendors & Products Weaviate
Weaviate verba
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T09:00:11.501Z

Reserved: 2026-10-03T17:00:34.395Z

Link: CVE-2026-105145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T11:16:31.197

Modified: 2026-10-04T11:16:31.197

Link: CVE-2026-105145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T12:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control