CVE 2.6 LOW

Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit log_CVE-2025-64326

2.6 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Description

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.

Basic Information

ID CVE-2025-64326
Source GitHub_M
Published Nov 6, 2025 at 20:55
Modified Nov 6, 2025 at 21:18

Affected Product

Vendor WeblateOrg
Product weblate
Version < 5.14.1
Affected Versions WeblateOrg weblate < 5.14.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.