Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gr35-vpx2-qxhc Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 21:00:00 +0000

Type Values Removed Values Added
Description Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
Title Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit log
Weaknesses CWE-212
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-06T21:18:02.834Z

Reserved: 2025-10-30T17:40:52.028Z

Link: CVE-2025-64326

cve-icon Vulnrichment

Updated: 2025-11-06T21:17:54.295Z

cve-icon NVD

Status : Received

Published: 2025-11-06T21:15:43.957

Modified: 2025-11-06T21:15:43.957

Link: CVE-2025-64326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.