Weblate is vulnerable to RCE through Git config file overwrite
Critical severity
GitHub Reviewed
Published
Dec 18, 2025
in
WeblateOrg/weblate
•
Updated Feb 6, 2026
Description
Published by the National Vulnerability Database
Dec 18, 2025
Published to the GitHub Advisory Database
Dec 18, 2025
Reviewed
Dec 18, 2025
Last updated
Feb 6, 2026
Impact
It was possible to overwrite Git configuration remotely and override some of its behavior.
Resources
Thanks to Jason Marcello for responsible disclosure.
References