CVE-2025-64725: Weblate has improper validation upon invitation acceptance
Impact
It was possible to accept an invitation opened by a different Weblate user.
Patches
https://github.com/WeblateOrg/weblate/pull/16913
Workarounds
Users should avoid leaving Weblate sessions with an unattended opened invitation.
References
Thanks to Nahid0x for responsibly disclosing this vulnerability to Weblate.
Other sources
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64725?
CVE-2025-64725 has been identified as a vulnerability that allows one Weblate user to accept invitations meant for another user.
How do I fix CVE-2025-64725?
To fix CVE-2025-64725, update Weblate to version 5.15 or later.
What are the potential consequences of CVE-2025-64725?
The potential consequences of CVE-2025-64725 include unauthorized access to user accounts and associated data.
What should users do to mitigate risks associated with CVE-2025-64725?
Users should avoid leaving Weblate sessions unattended while invitations are open as a mitigation measure.
Which versions of Weblate are affected by CVE-2025-64725?
Versions of Weblate below 5.15 are affected by CVE-2025-64725.