Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
References
Configurations
History
06 Feb 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Jan 2026, 16:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/WeblateOrg/weblate/pull/17330 - Issue Tracking | |
| References | () https://github.com/WeblateOrg/weblate/pull/17345 - Issue Tracking | |
| References | () https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1 - Release Notes | |
| References | () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-8vcg-cfxj-p5m3 - Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | |
| First Time |
Weblate
Weblate weblate |
18 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 23:15
Updated : 2026-02-06 20:16
NVD link : CVE-2025-68398
Mitre link : CVE-2025-68398
CVE.ORG link : CVE-2025-68398
JSON object : View
Products Affected
weblate
- weblate
CWE
CWE-20
Improper Input Validation
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-434Unrestricted Upload of File with Dangerous Type
NVD-CWE-noinfo