PT-2025-51349 · Weblate · Weblate

Naxus-Audit

·

Published

2025-12-15

·

Updated

2026-01-21

·

CVE-2025-67492

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.15
Description Weblate is a web-based localization tool. Versions prior to 5.15 were susceptible to unauthorized triggering of repository updates through a specially crafted webhook payload. Disabling webhooks using ENABLE HOOKS can be used as a temporary workaround.
Recommendations Update to version 5.15 or later. As a temporary workaround, disable webhooks using ENABLE HOOKS.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-67492
GHSA-PJ86-258H-QRVF
PYSEC-2025-232

Affected Products

Weblate