CVE-2025-61587 is an open redirect vulnerability affecting Weblate versions 5.13.2 and below, specifically when configured with Anubis and without the REDIRECT_DOMAINS setting. An attacker can craft a malicious URL on a legitimate Weblate domain to redirect users to an attacker-controlled site, potentially leading to drive-by downloads of malicious files. This vulnerability is rated Medium severity (CVSS 6.1) due to its network-based attack vector, low attack complexity, and requirement for user interaction. Its potential impact includes low confidentiality and integrity compromise. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.13.3CPE matchmatch criteria | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.