VulnerabilityAnalyzed
CVE-2025-64326
In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log.
LOW 3.5EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-212
- Affected
- weblate/weblate
- Source
- security-advisories@github.com
References
- https://github.com/WeblateOrg/weblate/pull/16781Issue Tracking
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-gr35-vpx2-qxhcPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.