
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67492 is a vulnerability in Weblate, a web-based localization tool, where an over-permissive webhook endpoint allows unauthenticated attackers to trigger mass repository updates and enumerate components via a crafted webhook payload. It affects all Weblate versions prior to 5.15 and was disclosed on December 15, 2025. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Weblate Advisory).
The root cause is classified as CWE-1286 (Improper Validation of Syntactic Correctness of Input): the webhook endpoint in weblate/trans/views/hooks.py did not validate that the full_name field in incoming webhook payloads was well-formed (i.e., contained a slash and met a minimum length) before using it in repository matching queries. An unauthenticated remote attacker could send a crafted HTTP POST request with a blank, too-short, or otherwise malformed full_name value, causing the endpoint to perform overly broad repository lookups and trigger updates across many repositories. The fix, merged in PR #17221, introduces a validate_full_name() function that enforces the presence of a slash and a minimum length before the value is used (Weblate Advisory, Fix PR).
Successful exploitation allows an unauthenticated attacker to trigger repository update operations across many or all repositories configured in a Weblate instance, potentially causing unintended synchronization activity and resource consumption. Additionally, the over-permissive behavior enables component enumeration, exposing information about the internal structure of the Weblate deployment (confidentiality impact: Low). Integrity and availability impacts are rated None in the CVSS scoring, though mass update triggering could indirectly affect operational stability (Github Advisory, Weblate Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no user interaction, and is network-accessible, making it low-complexity to attempt. The EPSS score is approximately 0.019% (0.041% per Feedly), placing it in the 5th percentile for exploitation likelihood. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI (Github Advisory, Weblate Advisory).
/hooks/github/, /hooks/gitlab/, /hooks/bitbucket/) that accepts POST requests from version control platforms.full_name field (e.g., {"repository": {"full_name": ""}}).full_name validation, the endpoint performs an overly broad repository match, triggering update operations across many or all configured repositories./hooks/github/, /hooks/gitlab/, /hooks/bitbucket/, /hooks/gitea/, etc.) from unexpected or unknown IP addresses; requests with minimal or malformed JSON payloads.full_name values; abnormal spikes in repository update activity logged by Weblate.Upgrade Weblate to version 5.15 or later, which includes the fix that validates the full_name field in webhook payloads before use (PR #17221). As an immediate workaround for those unable to upgrade, disable webhooks entirely by setting ENABLE_HOOKS = False in the Weblate configuration. Additionally, restricting webhook endpoint access to trusted IP ranges (e.g., known VCS provider IP ranges) at the network or reverse proxy level can reduce exposure (Weblate Advisory, Fix PR).
The vulnerability was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI, and the Weblate maintainer (nijel) published the advisory and merged the fix on December 15, 2025. The issue received routine coverage from vulnerability tracking services including CIRCL Vulnerability Lookup, CVEFeed, and VulDB, with no notable broader media coverage or significant community debate observed (Weblate Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."