Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61587

22
FAUCET Score

CVE-2025-61587 is an open redirect vulnerability affecting Weblate versions 5.13.2 and below, specifically when configured with Anubis and without the REDIRECT_DOMAINS setting. An attacker can craft a malicious URL on a legitimate Weblate domain to redirect users to an attacker-controlled site, potentially leading to drive-by downloads of malicious files. This vulnerability is rated Medium severity (CVSS 6.1) due to its network-based attack vector, low attack complexity, and requirement for user interaction. Its potential impact includes low confidentiality and integrity compromise. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has also received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.13.3CPE matchmatch criteria
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
29.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 30th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / WeblateOrg/docker/commit/76518342f65b8af8c2b7f7c5d37f84813c1253a1
Patch
github.com / WeblateOrg/weblate/commit/6b3d73a310279b5630bca8cbd9ea0be28bc67b63
Patch
github.com / WeblateOrg/weblate/commit/ec3b900f8a52c5c992d9e7014f09397e159ac381
Patch
github.com / WeblateOrg/weblate/security/advisories/GHSA-3xhv-r4gx-xw99
ExploitVendor Advisory