Executive brief
Verba, an open-source application used for building AI-powered search and chat systems, contains a security flaw that allows unauthorized individuals to force the server to make internal network requests. An attacker can use this to bypass network security and access sensitive internal data, such as database credentials or cloud service metadata. This is particularly serious because the application has been discontinued and will not receive a formal security patch.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Verba RAG application due to a lack of authentication and input validation on the WebSocket import endpoint. Attackers can connect to '/ws/import_files' without credentials and provide a malicious configuration to the 'HTMLReader' component. The backend uses the 'aiohttp' library to fetch user-supplied URLs without verifying the destination. This allows an attacker to probe internal network services, access co-located databases like Weaviate, or query cloud metadata services (e.g., 169.254.169.254) to steal IAM credentials. The project was archived in June 2024 and no official patch is available; users should implement network-level restrictions or migrate to supported alternatives.
Affected products
- Weaviate Verba (goldenverba) <= 2.1.3
Timeline
- 2026-06-02: disclosed: Vulnerability reported to vendor via email
- 2026-06-08: other: Repository archived by owner and project discontinued
- 2026-07-21: advisory: CVE published and public disclosure released