W
eblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
References
Configurations
History
06 Feb 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Jan 2026, 16:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Weblate weblate
Weblate |
|
| CPE | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| References | () https://github.com/WeblateOrg/weblate/pull/17330 - Issue Tracking | |
| References | () https://github.com/WeblateOrg/weblate/pull/17345 - Issue Tracking | |
| References | () https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1 - Release Notes | |
| References | () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-8vcg-cfxj-p5m3 - Vendor Advisory |
19 Dec 2025, 18:00
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 23:15
Updated : 2026-02-06 20:16
NVD link : CVE-2025-68398
Mitre link : CVE-2025-68398
CVE.ORG link : CVE-2025-68398
JSON object : View
CWE
CWE-20
Improper Input Validation
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-434Unrestricted Upload of File with Dangerous Type
NVD-CWE-noinfo