CVE-2025-68279 - Weblate has an arbitrary file read via symbolic links
CVE ID : CVE-2025-68279
Published : Dec. 18, 2025, 11:15 p.m. | 4 hours, 37 minutes ago
Description : Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Dec. 18, 2025, 11:15 p.m. | 4 hours, 37 minutes ago
Description : Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...