CVE-2025-68398
CRITICAL severity · CVSS 9.1 · Improper input validation
9.1CVSS CRITICAL
Summary
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredHigh
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-8vcg-cfxj-p5m3Advisory
- https://github.com/WeblateOrg/weblate/commit/4837a4154390f7c1d03c0e398aa6439dcfa361b4
- https://github.com/WeblateOrg/weblate/commit/dd8c9d7b00eebe28770fa0e2cd96126791765ea7
- https://github.com/WeblateOrg/weblate/pull/17330
- https://github.com/WeblateOrg/weblate/pull/17345
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1