Junglewise Threat Intelligence

CVE-2025-64326: Weblate information disclosure in audit logs

CVE-2025-64326 · Severity: low · CVSS 3.1 · Published 2025-11-05

Technologies: weblate (PyPI). Vendors: PyPI.

Executive brief

Weblate, a web-based translation platform, was found to inadvertently reveal the IP addresses of administrators to other users. When an administrator invites a new user to a project, their private IP address is recorded in an audit log that the invited user can access. This could allow unauthorized individuals to see the network location of project managers, potentially aiding in more targeted network attacks.

Technical details

An information disclosure vulnerability exists in Weblate versions prior to 5.14.1 due to improper removal of sensitive information in audit logs (CWE-212). When an administrator or project member triggers an invitation action, the system records the initiator's IP address in the audit log. These logs were accessible to the invited users, allowing them to view the administrator's IP address. Exploitation requires the attacker to have a low-privileged account (invited user) and involves high complexity as it relies on specific administrative actions. The issue has been patched in version 5.14.1.

Affected products

  • WeblateOrg weblate < 5.14.1

Timeline

  • 2025-11-05: disclosed
  • 2025-11-05: patched
  • 2025-11-05: advisory

References

Related threats