CVE 7.7 HIGH

Weblate has an arbitrary file read via symbolic links_CVE-2025-68279

7.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Description

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

Basic Information

ID CVE-2025-68279
Source GitHub_M
Published Dec 18, 2025 at 22:59

Affected Product

Vendor WeblateOrg
Product weblate
Version < 5.15.1
Affected Versions WeblateOrg weblate < 5.15.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.