GHSA-3pmh-24wp-xpf4MediumCVSS 4.3

Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)

Published
December 15, 2025
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

It was possible to retrieve user notification settings or list all users via API.

Patches

  • https://github.com/WeblateOrg/weblate/pull/17256

References

Thanks to Hector Ruiz Ruiz & NaxusAI for responsibly disclosing this vulnerability to Weblate.

🎯 Affected products1

  • pip/Weblate:< 5.15

🔗 References (5)