Описание
Weblate has improper validation upon invitation acceptance
Impact
It was possible to accept an invitation opened by a different Weblate user.
Patches
Workarounds
Users should avoid leaving Weblate sessions with an unattended opened invitation.
References
Thanks to Nahid0x for responsibly disclosing this vulnerability to Weblate.
Ссылки
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-m6hq-f4w9-qrjj
- https://nvd.nist.gov/vuln/detail/CVE-2025-64725
- https://github.com/WeblateOrg/weblate/pull/16913
- https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15
Пакеты
Наименование
Weblate
pip
Затронутые версииВерсия исправления
< 5.15
5.15
Связанные уязвимости
CVSS3: 9.8
nvd
около 2 месяцев назад
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.
CVSS3: 9.8
debian
около 2 месяцев назад
Weblate is a web based localization tool. In versions prior to 5.15, i ...