CVE-2025-68398: Weblate
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
Affected products
- Weblate Weblate: before 5.15.1 (fixed in 5.15.1)
Published 2025-12-18. Last modified 2026-09-30.