<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 20:48:08 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-68279 — Weblate has an arbitrary file read via symbolic links</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-68279</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; WeblateOrg weblate&lt;/p&gt;
&lt;p&gt;Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; WeblateOrg weblate&lt;/p&gt;
&lt;p&gt;Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-68279</guid>
    </item>
    <item>
      <title>GHSA-g925-f788-4jh7 — Weblate has an arbitrary file read via symbolic links</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g925-f788-4jh7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Weblate&lt;/p&gt;
&lt;p&gt;### Impact
It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;Thanks to Jason Marcello for responsible disclosure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Weblate&lt;/p&gt;
&lt;p&gt;### Impact
It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;Thanks to Jason Marcello for responsible disclosure.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g925-f788-4jh7</guid>
    </item>
  </channel>
</rss>
