CVE-2025-64326
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-06

Last updated on: 2025-12-04

Assigner: GitHub, Inc.

Description
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-06
Last Modified
2025-12-04
Generated
2026-06-16
AI Q&A
2025-11-06
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
weblate weblate to 5.14.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in Weblate versions 5.14 and below causes the IP address of the project member who invites a user to a project to be leaked in the audit log. The audit log, which includes IP addresses from admin-triggered actions, is viewable by invited users, exposing potentially sensitive IP information. This issue is fixed in version 5.14.1.

Impact Analysis

The vulnerability can lead to unintended disclosure of IP addresses of project members who invite users, potentially compromising privacy and exposing network information to users who should not have access to it. This could be used for tracking or profiling individuals involved in the project.

Mitigation Strategies

Upgrade Weblate to version 5.14.1 or later, as this version fixes the issue of IP address leakage in the audit log.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-64326. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart