{"id":"CVE-2025-64725","aliases":["GHSA-m6hq-f4w9-qrjj","PYSEC-2026-2042"],"title":"Weblate has improper validation upon invitation acceptance","summary":"Weblate has improper validation upon invitation acceptance","severity":"low","vendor":"weblate","product":"weblate","ecosystem":"pip","affected":["weblate < 5.15"],"patched":["weblate 5.15"],"published":"2025-12-15","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:58.670368920Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-m6hq-f4w9-qrjj","references":[{"url":"https://github.com/WeblateOrg/weblate/security/advisories/GHSA-m6hq-f4w9-qrjj"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64725"},{"url":"https://github.com/WeblateOrg/weblate/pull/16913"},{"url":"https://github.com/WeblateOrg/weblate/commit/02e904675f0608a6bbfbf9466eeccd9d022591e9"},{"url":"https://github.com/WeblateOrg/weblate"},{"url":"https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15"}],"tags":["osv","pip"],"epss":0.00349,"epssPercentile":0.28622,"ingestedAt":"2026-07-08T18:25:51.147Z","slug":"CVE-2025-64725","body":"## Overview\n\n### Impact\n\nIt was possible to accept an invitation opened by a different Weblate user.\n\n### Patches\n\n* https://github.com/WeblateOrg/weblate/pull/16913\n\n### Workarounds\n\nUsers should avoid leaving Weblate sessions with an unattended opened invitation.\n\n### References\n\nThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate.\n\n## Affected packages\n\n- `weblate < 5.15`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `weblate 5.15`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}