Vulnerability Description
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weblate | Weblate | < 5.15.1 |
Related Weaknesses (CWE)
References
- https://github.com/WeblateOrg/weblate/pull/17331Issue TrackingPatch
- https://github.com/WeblateOrg/weblate/pull/17356Issue TrackingPatch
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1Release Notes
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-g925-f788-4jh7Vendor Advisory
FAQ
What is CVE-2025-68279?
CVE-2025-68279 is a vulnerability with a CVSS score of 7.7 (HIGH). Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15....
How severe is CVE-2025-68279?
CVE-2025-68279 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-68279?
Check the references section above for vendor advisories and patch information. Affected products include: Weblate Weblate.