PatchSiren cyber security CVE debrief
CVE-2026-105145 Weaviate CVE debrief
A vulnerability was found in Weaviate Verba up to 2.1.3, affecting the get_environment function in goldenverba/components/util.py. This issue leads to information disclosure and can be exploited remotely. The exploit has been publicly disclosed, and although the vendor was notified, no response was received. Defenders should assess potential exposure and prioritize verification and monitoring of Weaviate Verba installations, especially those using version 2.1.3 or earlier. The vulnerability's impact on operational security and the lack of vendor response necessitate immediate attention.
- Vendor
- Weaviate
- Product
- Verba
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for Weaviate Verba installations, especially those using version 2.1.3 or earlier, should assess potential exposure and prioritize verification and monitoring.
Why it matters
Defenders should prioritize verifying exposure of Weaviate Verba installations, especially those using version 2.1.3 or earlier, and assess the potential for information disclosure due to the publicly disclosed exploit and unknown vendor response.
- Potential information disclosure requires verification
- Remote exploitation is possible
- Vendor response and remediation status are unknown
Technical summary
The vulnerability affects the get_environment function in goldenverba/components/util.py of Weaviate Verba up to 2.1.3, leading to information disclosure. The CVSS score is 5.5, and the vulnerability can be exploited remotely. The exploit has been publicly disclosed, and although the vendor was notified, no response was received. Defenders should prioritize verifying exposure of Weaviate Verba installations, especially those using version 2.1.3 or earlier, and assess the potential for information disclosure due to the publicly disclosed exploit and unknown vendor response.
Defensive priority
Defenders should prioritize verifying exposure of Weaviate Verba installations, especially those using version 2.1.3 or earlier, and assess the potential for information disclosure.
Recommended defensive actions
- Verify Weaviate Verba installations for version 2.1.3 or earlier
- Assess potential exposure to information disclosure
- Monitor for publicly disclosed exploits
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected components. However, the vendor's response and potential exploitation remain unknown.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105145 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105145
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105145 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105145
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/DReazer/63d8096046a058f9c7a533846db5e2ac
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105145
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/945744
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413370
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413370/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.