Executive brief
Weblate, a web-based translation tool, is vulnerable to a security flaw where authorized project administrators can probe internal network services. By configuring a malicious translation service URL, an attacker can force the server to make requests to internal systems and view parts of the response. This could lead to the exposure of sensitive information from internal infrastructure that is not otherwise accessible from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Weblate's machine translation configuration. Users with 'project.edit' permissions (typically the per-project Administration role) can specify arbitrary URLs for machinery services. During the configuration validation phase, the application performs an HTTP request to the user-provided URL. If the request fails or returns an error, Weblate reflects up to 200 characters of the response body back to the user in an error message. This allows for internal network scanning and partial data exfiltration from internal services. The issue is fixed in version 5.17.
Affected products
- WeblateOrg Weblate < 5.17
Timeline
- 2026-04-15: patched: Version 5.17 released
- 2026-04-16: advisory: GitHub Advisory published