Impact
The vulnerability arises from the get_environment function in the generate_stream endpoint of Weaviate Verba, allowing remote attackers to retrieve environment information that should remain confidential; this flaw reflects weaknesses in CWE-200 (Information Exposure) and CWE-284 (Improper Authorization) and could enable an attacker to access configuration details or other sensitive data.
Affected Systems
This issue affects installations of Weaviate Verba version 2.1.3 or earlier; the vulnerable code resides in goldenverba/components/util.py within the generate_stream endpoint.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity impact, and no EPSS score is available, although publicly disclosed exploits are known; the vulnerability is not listed in CISA's KEV catalog, but the attack vector is remote, meaning an attacker can attempt exploitation from any network location that can reach the generate_stream API.
OpenCVE Enrichment