{"data":{"id":"c827a7bf-3967-4eaf-8295-3c811c25cd00","title":"CVE-2026-105145: A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function…","summary":"A vulnerability has been found in Weaviate Verba up to 2.1.3. The function get_environment in goldenverba/components/util.py, reached through the generate_stream Endpoint component, can be manipulated to disclose information. The attack can be launched remotely, and the exploit is public. The vendor was contacted early but did not respond.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105145","publishedAt":"2026-10-04T11:16:31.197Z","cveId":"CVE-2026-105145","cweIds":["CWE-200","CWE-284"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Weaviate Verba"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00286,"epssCheckedAt":"2026-10-10T02:57:07.563Z","kevDateAdded":null,"advisoryAliases":["GHSA-8456-r8c8-j656"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:59.558Z","patchAvailable":null,"disclosureDate":"2026-10-04T11:16:31.197Z","capecIds":["CAPEC-116"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}