GHSA-2q2q-jr9g-v9rfHighCVSS 8.1

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.

Patches

  • https://github.com/WeblateOrg/weblate/pull/19970

References

Parts of this issue were independently reported by four reporters:

🎯 Affected products1

  • pip/Weblate:< 2026.7

🔗 References (5)