Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
History

Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Weblate
Weblate weblate
Vendors & Products Weblate
Weblate weblate

Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 21:00:00 +0000

Type Values Removed Values Added
Description Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
Title Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit log
Weaknesses CWE-212
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-06T20:55:17.594Z

Updated: 2025-11-06T21:18:02.834Z

Reserved: 2025-10-30T17:40:52.028Z

Link: CVE-2025-64326

cve-icon Vulnrichment

Updated: 2025-11-06T21:17:54.295Z

cve-icon NVD

Status : Received

Published: 2025-11-06T21:15:43.957

Modified: 2025-11-06T21:15:43.957

Link: CVE-2025-64326

cve-icon Redhat

No data.