GHSA-2q2q-jr9g-v9rfHighCVSS 8.1
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
🔗 CVE IDs covered (1)
📋 Description
Impact
The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.
Patches
- https://github.com/WeblateOrg/weblate/pull/19970
References
Parts of this issue were independently reported by four reporters:
🎯 Affected products1
- pip/Weblate:< 2026.7
🔗 References (5)
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-2q2q-jr9g-v9rf
- https://nvd.nist.gov/vuln/detail/CVE-2026-55228
- https://github.com/WeblateOrg/weblate/pull/19970
- https://github.com/WeblateOrg/weblate/commit/19babc99b05f2cc299b5090f90f79d8181f25d79
- https://github.com/advisories/GHSA-2q2q-jr9g-v9rf