id: PYSEC-2025-269 published: "2025-10-01T22:15:31.853Z" modified: "2026-07-13T05:52:33.037156Z" aliases: - CVE-2025-61587 - GHSA-3xhv-r4gx-xw99 details: Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. affected: - package: name: weblate ecosystem: PyPI purl: pkg:pypi/weblate ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 5.13.3 versions: - "1.9" - "2.0" - "2.1" - "2.10" - 2.10.1 - "2.11" - "2.12" - "2.13" - 2.13.1 - "2.14" - 2.14.1 - "2.15" - "2.16" - "2.17" - 2.17.1 - "2.18" - "2.19" - 2.19.1 - "2.2" - "2.20" - "2.3" - "2.4" - "2.5" - "2.6" - "2.7" - "2.8" - "2.9" - "3.0" - 3.0.1 - "3.1" - 3.1.1 - "3.10" - 3.10.1 - 3.10.2 - 3.10.3 - "3.11" - 3.11.1 - 3.11.2 - 3.11.3 - "3.2" - 3.2.1 - 3.2.2 - "3.3" - "3.4" - "3.5" - 3.5.1 - "3.6" - 3.6.1 - "3.7" - 3.7.1 - "3.8" - "3.9" - 3.9.1 - "4.0" - 4.0.1 - 4.0.2 - 4.0.3 - 4.0.4 - "4.1" - 4.1.1 - "4.10" - 4.10.1 - "4.11" - 4.11.1 - 4.11.2 - "4.12" - 4.12.1 - 4.12.2 - "4.13" - 4.13.1 - "4.14" - 4.14.1 - 4.14.2 - "4.15" - 4.15.1 - 4.15.2 - "4.16" - 4.16.1 - 4.16.2 - 4.16.3 - 4.16.4 - "4.17" - "4.18" - 4.18.1 - 4.18.2 - "4.2" - 4.2.1 - 4.2.2 - "4.3" - 4.3.1 - 4.3.2 - "4.4" - 4.4.1 - 4.4.2 - "4.5" - 4.5.1 - 4.5.2 - 4.5.3 - "4.6" - 4.6.1 - 4.6.2 - "4.7" - 4.7.1 - 4.7.2 - "4.8" - 4.8.1 - "4.9" - 4.9.1 - "5.0" - 5.0.1 - 5.0.2 - "5.1" - 5.1.1 - "5.10" - 5.10.1 - 5.10.2 - 5.10.3 - 5.10.4 - "5.11" - 5.11.1 - 5.11.3 - 5.11.4 - 5.12.1 - 5.12.2 - "5.13" - 5.13.1 - 5.13.2 - "5.2" - 5.2.1 - "5.3" - 5.3.1 - "5.4" - 5.4.1 - 5.4.2 - 5.4.3 - "5.5" - 5.5.2 - 5.5.3 - 5.5.4 - 5.5.5 - "5.6" - 5.6.1 - 5.6.2 - "5.7" - 5.7.1 - 5.7.2 - 5.8.1 - 5.8.2 - 5.8.3 - 5.8.4 - 5.9.1 - 5.9.2 ecosystem_specific: {} references: - type: FIX url: https://github.com/WeblateOrg/docker/commit/76518342f65b8af8c2b7f7c5d37f84813c1253a1 - type: FIX url: https://github.com/WeblateOrg/weblate/commit/6b3d73a310279b5630bca8cbd9ea0be28bc67b63 - type: FIX url: https://github.com/WeblateOrg/weblate/commit/ec3b900f8a52c5c992d9e7014f09397e159ac381 - type: EVIDENCE url: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3xhv-r4gx-xw99 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N