Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gr35-vpx2-qxhc: Weblate leaks the IP of project member inviting user to be reviewer in Audit log

Summary

Weblate leaks the IP address of the project member inviting the user to the project in the audit log.

Details

The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.

Impact

The inviting user’s (admin’s) IP address could be leaked to invited users.

ghsa
#web#git#intel

Skip to content

Navigation Menu

    • AI CODE CREATION

      • GitHub CopilotWrite better code with AI

      • GitHub SparkBuild and deploy intelligent apps

      • GitHub ModelsManage and compare prompts

      • MCP RegistryNewDiscover and integrate external tools

View all features
  • Pricing

Provide feedback

Saved searches****Use saved searches to filter your results more quickly

Sign up

Appearance settings

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-64326

Weblate leaks the IP of project member inviting user to be reviewer in Audit log

Low severity GitHub Reviewed Published Nov 5, 2025 in WeblateOrg/weblate • Updated Nov 5, 2025

Package

pip weblate (pip)

Affected versions

< 5.14.1

Description

Summary

Weblate leaks the IP address of the project member inviting the user to the project in the audit log.

Details

The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.

Impact

The inviting user’s (admin’s) IP address could be leaked to invited users.

References

  • GHSA-gr35-vpx2-qxhc
  • WeblateOrg/weblate#16781
  • WeblateOrg/weblate@b847e97

Published to the GitHub Advisory Database

Nov 5, 2025

EPSS score

ghsa: Latest News

GHSA-wwqv-p2pp-99h5: LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer