Executive brief
Weblate, a web-based translation management system, contained a security flaw in its programming interface (API). An authenticated user could exploit this to view a full list of other users on the system and access their private notification settings. This could lead to the exposure of internal user lists and organizational project structures.
Technical details
Weblate is vulnerable to Insecure Direct Object Reference (IDOR) and broken authorization within its REST API. The flaw allows an authenticated attacker with low privileges to bypass intended access controls to list all registered users and retrieve individual user notification settings. This systematic enumeration is caused by improper authorization checks (CWE-285) when accessing specific API endpoints. The vulnerability is addressed in Weblate version 5.15.
Affected products
- WeblateOrg Weblate < 5.15
Timeline
- 2025-12-15: advisory: GitHub Advisory published
- 2025-12-15: patched: Fix merged in version 5.15