Executive brief
Weblate, a web-based translation and localization platform, contained a security flaw in its programming interface (API). An authenticated user could exploit this to determine the existence of translation projects and components they were not authorized to see. This could lead to the exposure of private project names or internal organizational structures.
Technical details
An information disclosure vulnerability exists in Weblate's REST API due to insufficient access-filtered querysets in several endpoints, including screenshots, tasks, and component links. Specifically, the application failed to properly validate if a requesting user had permissions for a specific translation or component before returning a response that confirmed its existence (CWE-203). An authenticated attacker could use these API parameters to enumerate the names and existence of private projects or translations they cannot otherwise access. The fix, introduced in version 5.17.1, implements 'filter_access(user)' checks and ensures that lookups for categories and components are strictly scoped to the projects the user is authorized to view.
Affected products
- WeblateOrg Weblate < 5.17.1
Timeline
- 2026-04-27: patched: Fix committed to repository
- 2026-04-30: advisory: Release 5.17.1 published
- 2026-05-07: disclosed: CVE published