CVE-2025-68279: Weblate
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
Affected products
- Weblate Weblate: before 5.15.1 (fixed in 5.15.1)
Published 2025-12-18. Last modified 2026-06-17.