VDB
KO
HIGH 7.7

GHSA-g925-f788-4jh7

Weblate has an arbitrary file read via symbolic links

Details

### Impact It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.

### Resources

Thanks to Jason Marcello for responsible disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / weblate
Introduced in: 0 Fixed in: 5.15.1
Fix pip install --upgrade 'weblate>=5.15.1'

References