GHSA-gr35-vpx2-qxhcLowCVSS 2.6
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
🔗 CVE IDs covered (1)
📋 Description
Summary
Weblate leaks the IP address of the project member inviting the user to the project in the audit log.
Details
The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.
Impact
The inviting user's (admin's) IP address could be leaked to invited users.
🎯 Affected products1
- pip/weblate:< 5.14.1
🔗 References (6)
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-gr35-vpx2-qxhc
- https://github.com/WeblateOrg/weblate/pull/16781
- https://github.com/WeblateOrg/weblate/commit/b847e9756a0a6f7659ef20fa9f34846ca862c574
- https://nvd.nist.gov/vuln/detail/CVE-2025-64326
- https://github.com/pypa/advisory-database/tree/main/vulns/weblate/PYSEC-2025-230.yaml
- https://github.com/advisories/GHSA-gr35-vpx2-qxhc