Weblate has an arbitrary file read via symbolic links
Description
Published to the GitHub Advisory Database
Dec 18, 2025
Reviewed
Dec 18, 2025
Published by the National Vulnerability Database
Dec 18, 2025
Last updated
Dec 20, 2025
Impact
It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.
Resources
Thanks to Jason Marcello for responsible disclosure.
References