GHSA-pj86-258h-qrvfMediumCVSS 5.3
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
🔗 CVE IDs covered (1)
📋 Description
Impact
It was possible to trigger repository updates for many repositories via a crafted webhook payload.
Patches
- https://github.com/WeblateOrg/weblate/pull/17221
Workarounds
Disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability.
References
Thanks to Hector Ruiz Ruiz & NaxusAI for responsibly disclosing this vulnerability to us.
🎯 Affected products1
- pip/Weblate:< 5.15
🔗 References (5)
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-pj86-258h-qrvf
- https://github.com/WeblateOrg/weblate/pull/17221
- https://nvd.nist.gov/vuln/detail/CVE-2025-67492
- https://github.com/pypa/advisory-database/tree/main/vulns/weblate/PYSEC-2025-232.yaml
- https://github.com/advisories/GHSA-pj86-258h-qrvf