CVE-2025-68398: Weblate has git config file overwrite vulnerability that leads to remote code execution
Impact
It was possible to overwrite Git configuration remotely and override some of its behavior.
Resources
Thanks to Jason Marcello for responsible disclosure.
Other sources
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68398?
CVE-2025-68398 allows for a remote overwrite of Git configuration which can impact the behavior of Git.
How do I fix CVE-2025-68398?
To fix CVE-2025-68398, upgrade Weblate to version 5.15.1 or later.
What versions of Weblate are affected by CVE-2025-68398?
Weblate versions prior to 5.15.1 are affected by CVE-2025-68398.
What is the main impact of CVE-2025-68398?
The main impact of CVE-2025-68398 is the potential for remote users to inadvertently change Git configurations.
Who disclosed CVE-2025-68398?
CVE-2025-68398 was disclosed responsibly by Jason Marcello.