CVE-2025-68279 - Weblate has an arbitrary file read via symbolic links

CVE-2025-68279 - Weblate has an arbitrary file read via symbolic links

CVE ID : CVE-2025-68279 Published : Dec. 18, 2025, 11:15 p.m. | 37 minutes ago Description : Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 18, 2025

Source: Telegram CVE Monitor