Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g925-f788-4jh7

Опубликовано: 18 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Weblate has an arbitrary file read via symbolic links

Impact

It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.

Resources

Thanks to Jason Marcello for responsible disclosure.

Пакеты

Наименование

Weblate

pip
Затронутые версииВерсия исправления

< 5.15.1

5.15.1

EPSS

Процентиль: 18%
0.00056
Низкий

7.7 High

CVSS3

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 7.7
nvd
около 2 месяцев назад

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

CVSS3: 7.7
debian
около 2 месяцев назад

Weblate is a web based localization tool. In versions prior to 5.15.1, ...

EPSS

Процентиль: 18%
0.00056
Низкий

7.7 High

CVSS3

Дефекты

CWE-22
CWE-59