VDB
KO
CRITICAL 9.1

GHSA-8vcg-cfxj-p5m3

Weblate is vulnerable to RCE through Git config file overwrite

Details

### Impact

It was possible to overwrite Git configuration remotely and override some of its behavior.

### Resources

Thanks to Jason Marcello for responsible disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / weblate
Introduced in: 0 Fixed in: 5.15.1
Fix pip install --upgrade 'weblate>=5.15.1'

References