Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8vcg-cfxj-p5m3 | Weblate is vulnerable to RCE through Git config file overwrite |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue. | |
| Title | Weblate has git config file overwrite vulnerability that leads to remote code execution | |
| Weaknesses | CWE-20 CWE-22 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-18T23:00:57.790Z
Reserved: 2025-12-16T21:59:48.534Z
Link: CVE-2025-68398
No data.
Status : Received
Published: 2025-12-18T23:15:49.720
Modified: 2025-12-18T23:15:49.720
Link: CVE-2025-68398
No data.
OpenCVE Enrichment
No data.
Github GHSA