CVE-2025-64326
published 2025-11-06CVE-2025-64326: Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in…
PriorityP413low3.5CVSS 3.1
AVNACLPRLUIRSUCLINAN
EPSS
0.19%
8.5th percentile
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.14.1 | 5.14.1 |
| weblate | weblate | >= 0 < 5.14.1 | 5.14.1 |
| weblateorg | weblate | < 5.14.1 | 5.14.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
osv·2025-11-05
CVE-2025-64326 [LOW] Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
### Summary
Weblate leaks the IP address of the project member inviting the user to the project in the audit log.
### Details
The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.
### Impact
The inviting user's (admin's) IP address could be leaked to invited users.
GHSA
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
ghsa·2025-11-05
CVE-2025-64326 [LOW] CWE-212 Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
### Summary
Weblate leaks the IP address of the project member inviting the user to the project in the audit log.
### Details
The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.
### Impact
The inviting user's (admin's) IP address could be leaked to invited users.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-06
Published