GHSA-9p4g-9hh7-7mj3MediumCVSS 5.3

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route,...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances.

🔗 References (6)