CVE-2025-68279Path Traversal in Weblate

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 78.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18

Description

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDweblate/weblate< 5.15.1
PyPIweblate/weblate< 5.15.1
CVEListV5weblateorg/weblate< 5.15.1

Patches

🔴Vulnerability Details

2
OSV
Weblate has an arbitrary file read via symbolic links2025-12-18
GHSA
Weblate has an arbitrary file read via symbolic links2025-12-18

🕵️Threat Intelligence

1
Wiz
CVE-2025-68279 Impact, Exploitability, and Mitigation Steps | Wiz