CVE-2025-68279: Weblate has an arbitrary file read via symbolic links
Impact It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.
Resources
Thanks to Jason Marcello for responsible disclosure.
Other sources
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68279?
CVE-2025-68279 is considered a high severity vulnerability due to the potential for unauthorized access to arbitrary files on the server.
How do I fix CVE-2025-68279?
To resolve CVE-2025-68279, update to Weblate version 5.15.1 or later.
What systems are affected by CVE-2025-68279?
CVE-2025-68279 affects Weblate versions prior to 5.15.1.
What is the nature of the vulnerability in CVE-2025-68279?
CVE-2025-68279 allows the reading of arbitrary files on the server file system through crafted symbolic links.
Who disclosed CVE-2025-68279?
CVE-2025-68279 was responsibly disclosed by Jason Marcello.