CVE-2025-68279
Impact
It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.
Resources
Thanks to Jason Marcello for responsible disclosure.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-g925-f788-4jh7, https://nvd.nist.gov/vuln/detail/CVE-2025-68279, https://github.com/WeblateOrg/weblate/pull/17331, https://github.com/WeblateOrg/weblate/pull/17356, https://github.com/WeblateOrg/weblate, https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1
