{"id":"CVE-2025-64725","aliases":["GHSA-m6hq-f4w9-qrjj","PYSEC-2026-2042"],"url":"https://o3.security/vulnerability/CVE-2025-64725","summary":"Weblate has improper validation upon invitation acceptance","details":"### Impact\n\nIt was possible to accept an invitation opened by a different Weblate user.\n\n### Patches\n\n* https://github.com/WeblateOrg/weblate/pull/16913\n\n### Workarounds\n\nUsers should avoid leaving Weblate sessions with an unattended opened invitation.\n\n### References\n\nThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate.","published":"2025-12-15T20:21:06.867Z","modified":"2026-08-12T03:51:08.825780268Z","cvss":null,"epss":{"score":0.00349,"percentile":0.28431,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"weblate","fixedVersion":"5.15"}],"fix":{"url":"https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9","label":"WeblateOrg/weblate@02e9046"},"references":[{"type":"WEB","url":"https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64725.json"},{"type":"ADVISORY","url":"https://github.com/WeblateOrg/weblate/security/advisories/GHSA-m6hq-f4w9-qrjj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64725"},{"type":"FIX","url":"https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9"},{"type":"FIX","url":"https://github.com/WeblateOrg/weblate/pull/16913"},{"type":"PACKAGE","url":"https://github.com/WeblateOrg/weblate"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:08.825780268Z"}}