Impact
Verba RAG application version 2.1.3 contains an unauthenticated SSRF vulnerability that allows an attacker to instruct the backend to perform arbitrary HTTP GET requests by supplying attacker‑controlled URLs in the WebSocket import endpoint’s HTMLReader configuration. Once triggered, the server can reach internal services, including database endpoints or cloud instance metadata services, and retrieve sensitive credentials or data. This flaw is identified with CWE‑918 and permits a remote actor to exfiltrate confidential information without needing authentication.
Affected Systems
The vulnerability is found in the Weaviate Verba product, specifically version 2.1.3 of the Verba RAG application. No other versions are reported as affected in the provided data.
Risk and Exploitability
The CVSS score of 9.2 rank this issue as high‑severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation observed to date. Though not listed in the CISA KEV catalog, the attack vector requires remote access to the exposed WebSocket endpoint (/ws/import_files) and the ability to supply arbitrary URLs; if such access is available, an attacker can pull internal credentials or confidential data across the network.
OpenCVE Enrichment