ZeroHour

CVE-2025-68279

CVSS 3.1
6.5 medium
EPSS
<1%p34
Published
()
Modified
Description

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

Vendors
weblate
Products
weblate
Weakness
CWE-22, CWE-59, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.