CVE-2025-61587
Severity CVSS v4.0:
LOW
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
01/10/2025
Last modified:
07/10/2025
Description
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | 5.13.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/WeblateOrg/docker/commit/76518342f65b8af8c2b7f7c5d37f84813c1253a1
- https://github.com/WeblateOrg/weblate/commit/6b3d73a310279b5630bca8cbd9ea0be28bc67b63
- https://github.com/WeblateOrg/weblate/commit/ec3b900f8a52c5c992d9e7014f09397e159ac381
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3xhv-r4gx-xw99
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3xhv-r4gx-xw99



