CVE-2025-66407 Overview
CVE-2025-66407 is a server-side request forgery (SSRF) vulnerability in Weblate, a web-based localization tool. The flaw exists in the Create Component functionality, which allows authorized users to specify a repository URL when adding a new translation component. Prior to version 5.15, Weblate does not validate or sanitize the repository URL when the Mercurial backend is selected. Attackers can supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network ranges, and file:// URIs. The Mercurial backend then exposes the full server-side HTTP response back to the requester. Weblate 5.15 fixes the issue.
Critical Impact
In cloud deployments, attackers can query internal-only endpoints such as cloud metadata services, potentially exposing instance credentials and enabling full environment compromise.
Affected Products
- Weblate versions prior to 5.15
- Deployments with Mercurial enabled in VCS_BACKENDS
- Cloud-hosted Weblate instances exposing metadata endpoints on link-local addresses
Discovery Timeline
- 2025-12-16 - CVE-2025-66407 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66407
Vulnerability Analysis
The Create Component workflow accepts a version control system selection and a repository URL. When the user chooses the Mercurial backend, Weblate invokes the underlying VCS client against the supplied URL without protocol allow-listing or hostname validation. The application then returns the server-side HTTP response body inside its error or status output, giving the attacker a read primitive against arbitrary network destinations reachable by the Weblate server.
The issue is tracked under CWE-918: Server-Side Request Forgery and CWE-352: Cross-Site Request Forgery. The Git backend is not affected because it already blocks the file:// protocol and does not echo HTTP response bodies through error messages.
Root Cause
The repository URL field on the component-creation endpoint lacks input validation and scheme restrictions. The Mercurial adapter does not sanitize the URL before passing it to the client, and its error-handling path surfaces the raw upstream response to the caller. This combination converts a component-creation feature into a general-purpose request proxy.
Attack Vector
An authenticated user with permission to create components submits a crafted repository URL pointing at an internal service. Targets include cloud metadata endpoints such as the AWS Instance Metadata Service at http://169.254.169.254/latest/meta-data/, internal admin dashboards on 127.0.0.1, and file:// URIs referencing paths like /etc/passwd or /proc/self/environ. The response content is returned to the attacker. Even when file contents are not returned, differences between error messages for existing and missing files enable filesystem enumeration.
No verified public exploit code is available. See the Weblate security advisory GHSA-hfpv-mc5v-p9mm for maintainer-provided technical details.
Detection Methods for CVE-2025-66407
Indicators of Compromise
- Weblate component-creation requests where the repository URL targets 127.0.0.1, 169.254.169.254, RFC1918 ranges, or uses the file:// scheme.
- Outbound Mercurial (hg) process activity from the Weblate host directed at internal IP addresses or cloud metadata endpoints.
- Repeated failed component-creation attempts from a single account probing varying hostnames or file paths.
Detection Strategies
- Parse Weblate application logs for Component create actions and extract the repo parameter for URL-scheme and destination-IP analysis.
- Correlate authenticated user sessions with unusual outbound HTTP or file:// access originating from the Weblate service account.
- Alert on any process invocation of hg clone or hg identify with non-standard destinations from the application host.
Monitoring Recommendations
- Enable egress filtering telemetry from the Weblate host and log connections to link-local and loopback ranges.
- Monitor cloud metadata service access using provider-native tooling such as AWS IMDSv2 enforcement logs or GCP metadata audit logs.
- Track configuration drift on VCS_BACKENDS to detect reintroduction of the Mercurial backend after remediation.
How to Mitigate CVE-2025-66407
Immediate Actions Required
- Upgrade Weblate to version 5.15 or later, which validates repository URLs and removes the response-echo behavior in the Mercurial backend.
- If upgrade is not immediate, remove mercurial from the VCS_BACKENDS setting to eliminate the vulnerable code path.
- Audit recent component-creation activity for suspicious repository URLs targeting internal addresses or file:// URIs.
- Enforce IMDSv2 with hop-limit restrictions on AWS instances to reduce impact of metadata-service probing.
Patch Information
The fix is included in Weblate 5.15. Review the upstream changes in Weblate Pull Request #17102 and Weblate Pull Request #17103, and the coordinated disclosure in GHSA-hfpv-mc5v-p9mm.
Workarounds
- Remove Mercurial from VCS_BACKENDS in the Weblate configuration; the Git backend is not affected.
- Restrict Create Component permissions to a small set of trusted administrators until patched.
- Apply network egress controls on the Weblate host to block access to loopback, link-local, and internal management ranges.
# settings.py - remove Mercurial from enabled VCS backends
VCS_BACKENDS = (
"weblate.vcs.git.GitRepository",
"weblate.vcs.git.GitWithGerritRepository",
"weblate.vcs.git.SubversionRepository",
"weblate.vcs.git.GithubRepository",
"weblate.vcs.git.GitLabRepository",
# "weblate.vcs.mercurial.HgRepository", # disabled - CVE-2025-66407
)
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
