Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8vcg-cfxj-p5m3 | Weblate is vulnerable to RCE through Git config file overwrite |
Fri, 06 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* |
Sat, 20 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weblate
Weblate weblate |
|
| Vendors & Products |
Weblate
Weblate weblate |
Thu, 18 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue. | |
| Title | Weblate has git config file overwrite vulnerability that leads to remote code execution | |
| Weaknesses | CWE-20 CWE-22 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T19:28:18.370Z
Reserved: 2025-12-16T21:59:48.534Z
Link: CVE-2025-68398
Updated: 2025-12-19T14:58:35.479Z
Status : Modified
Published: 2025-12-18T23:15:49.720
Modified: 2026-02-06T20:16:08.620
Link: CVE-2025-68398
No data.
OpenCVE Enrichment
Updated: 2025-12-19T09:15:45Z
Github GHSA