GHSA-pj86-258h-qrvfMediumCVSS 5.3

Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration

Published
December 15, 2025
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

It was possible to trigger repository updates for many repositories via a crafted webhook payload.

Patches

  • https://github.com/WeblateOrg/weblate/pull/17221

Workarounds

Disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability.

References

Thanks to Hector Ruiz Ruiz & NaxusAI for responsibly disclosing this vulnerability to us.

🎯 Affected products1

  • pip/Weblate:< 5.15

🔗 References (5)