# Weaviate patches high-severity Google credential leak in v1.39.3

> Weaviate shipped v1.39.3 to fix a high-severity flaw (CVSS 7.1, CVE pending) where an unvalidated apiEndpoint in its three Google modules could send the operator's Google credential to an attacker-chosen host.

- **Topic**: Models
- **Published**: 2026-10-02T06:17:38.017Z
- **Canonical URL**: https://highsignal.sh/stories/weaviate-patches-high-severity-google-credential-leak-in-v1-39-3-7914fb3e

## Why It Matters

The more serious of two attack paths ran through a GraphQL query parameter on generative-google, so an ordinary reader — not just schema writers — could redirect a live OAuth token scoped to cloud-platform; Weaviate Cloud, Marketplace and Enterprise customers were patched or notified under embargo. Worth noting against a day dominated by Gemini 4 Argon, this is a reminder that Google-auth-powered AI tooling carries infrastructure risk, not just model news.

## Primary Sources & Citations

- [Weaviate security release - High severity fix for credential disclosure in the Google modules](https://weaviate.io/blog/weaviate-security-release-googlemodules-2026) — *Weaviate Blog* (Reporting)

---

[← Back to Headlines](https://highsignal.sh/)
