Intel

AIKIDO-2024-10166

weaviate-client is vulnerable to SQL Injection

SQL Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 3, 2024

75

High Risk

This Affects:

pythonweaviate-client
1.0.0 - 3.26.4
Fixed in 3.26.5
4.0.0 - 4.6.6
Fixed in 4.6.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to SQL Injection.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

weaviate-client is vulnerable to SQL Injection in versions 1.0.0 - 3.26.4 and 4.0.0 - 4.6.6.

How to fix this

Upgrade weaviate-client to a patch version.