Junglewise Threat Intelligence

CVE-2025-67715: Weblate IDOR user and project enumeration in REST API

CVE-2025-67715 · Severity: medium · CVSS 4.3 · Published 2025-12-15

Technologies: weblate (PyPI). Vendors: PyPI.

Executive brief

Weblate, a web-based translation management system, contained a security flaw in its programming interface (API). An authenticated user could exploit this to view a full list of other users on the system and access their private notification settings. This could lead to the exposure of internal user lists and organizational project structures.

Technical details

Weblate is vulnerable to Insecure Direct Object Reference (IDOR) and broken authorization within its REST API. The flaw allows an authenticated attacker with low privileges to bypass intended access controls to list all registered users and retrieve individual user notification settings. This systematic enumeration is caused by improper authorization checks (CWE-285) when accessing specific API endpoints. The vulnerability is addressed in Weblate version 5.15.

Affected products

  • WeblateOrg Weblate < 5.15

Timeline

  • 2025-12-15: advisory: GitHub Advisory published
  • 2025-12-15: patched: Fix merged in version 5.15

References

Related threats