CVE 9.1 CRITICAL

Weblate has git config file overwrite vulnerability that leads to remote code execution_CVE-2025-68398

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

AI Analysis

Git configuration overwrite vulnerability leading to remote code execution

Basic Information

ID CVE-2025-68398
Source GitHub_M
Published Dec 18, 2025 at 23:00

Affected Product

Vendor WeblateOrg
Product weblate
Version < 5.15.1
Affected Versions WeblateOrg weblate < 5.15.1

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor WeblateOrg
Product Weblate
Version < 5.15.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.