VulnerabilityAnalyzed
CVE-2025-68279
In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.
MEDIUM 6.5EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-59, CWE-200
- Affected
- weblate/weblate
- Source
- security-advisories@github.com
References
- https://github.com/WeblateOrg/weblate/pull/17331Issue Tracking, Patch
- https://github.com/WeblateOrg/weblate/pull/17356Issue Tracking, Patch
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1Release Notes
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-g925-f788-4jh7Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.