GHSA-m6hq-f4w9-qrjj
Impact
It was possible to accept an invitation opened by a different Weblate user.
Patches
- https://github.com/WeblateOrg/weblate/pull/16913
Workarounds
Users should avoid leaving Weblate sessions with an unattended opened invitation.
References
Thanks to Nahid0x for responsibly disclosing this vulnerability to Weblate.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-m6hq-f4w9-qrjj, https://nvd.nist.gov/vuln/detail/CVE-2025-64725, https://github.com/WeblateOrg/weblate/pull/16913, https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9, https://github.com/WeblateOrg/weblate, https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15
