CVE-2025-61587 - CVE House
Back to Database
Status published Low CVE-2025-61587

Weblate integration with Anubis can lead to Open Redirect via redir parameter

Vulnerability Description

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-61587

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

weblate
Vulnerable Versions:
< 5.13.3

Timeline

Official Publish: October 1st, 2025
Last Modified: October 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)