Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vcg-cfxj-p5m3

Опубликовано: 18 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Weblate is vulnerable to RCE through Git config file overwrite

Impact

It was possible to overwrite Git configuration remotely and override some of its behavior.

Resources

Thanks to Jason Marcello for responsible disclosure.

Пакеты

Наименование

Weblate

pip
Затронутые версииВерсия исправления

< 5.15.1

5.15.1

EPSS

Процентиль: 45%
0.00222
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20
CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

CVSS3: 9.1
debian
около 2 месяцев назад

Weblate is a web based localization tool. In versions prior to 5.15.1, ...

EPSS

Процентиль: 45%
0.00222
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20
CWE-22