{"id":"CVE-2025-64725","aliases":["GHSA-m6hq-f4w9-qrjj","PYSEC-2026-2042"],"url":"https://o3.security/vulnerability/CVE-2025-64725","summary":"Weblate has improper validation upon invitation acceptance","details":"Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.","published":"2025-12-15T20:21:06.867Z","modified":"2026-08-08T03:48:15.687038084Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"weblate","fixedVersion":"5.15"}],"fix":{"url":"https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9","label":"WeblateOrg/weblate@02e9046"},"references":[{"type":"WEB","url":"https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64725.json"},{"type":"ADVISORY","url":"https://github.com/WeblateOrg/weblate/security/advisories/GHSA-m6hq-f4w9-qrjj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64725"},{"type":"FIX","url":"https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9"},{"type":"FIX","url":"https://github.com/WeblateOrg/weblate/pull/16913"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:15.687038084Z"}}