GHSA-gr35-vpx2-qxhcLowCVSS 2.6

Weblate leaks the IP of project member inviting user to be reviewer in Audit log

Published
November 5, 2025
Last Modified
June 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Weblate leaks the IP address of the project member inviting the user to the project in the audit log.

Details

The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.

Impact

The inviting user's (admin's) IP address could be leaked to invited users.

🎯 Affected products1

  • pip/weblate:< 5.14.1

🔗 References (6)