Unauthenticated Server-Side Request Forgery in Verba RAG Application by Verba
CVE-2026-65318

9.2CRITICAL

Key Information:

Vendor

Weaviate

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-65318?

The Verba RAG application version 2.1.3 is vulnerable to an unauthenticated server-side request forgery (SSRF) issue. This vulnerability allows attackers to connect to the /ws/import_files WebSocket endpoint without any authentication. By specifying malicious URLs within the HTMLReader configuration, attackers can manipulate the backend into issuing arbitrary HTTP GET requests. This could enable them to access sensitive internal resources, such as database endpoints or cloud instance metadata services, thereby exposing critical credentials.

Affected Version(s)

Verba 0 <= 2.1.3

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.