Information Disclosure in Weblate Localization Tool Vulnerability
CVE-2025-64326

2.6LOW

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-64326?

Weblate, a web-based localization tool, has a vulnerability that allows invited users to view the IP addresses of project members who trigger actions recorded in the audit log. This occurs in versions 5.14 and lower, where sensitive information could be accessed, posing a threat to user privacy. The issue was addressed in version 5.14.1, highlighting the importance of maintaining updated software to protect against such information disclosure risks.

Affected Version(s)

weblate < 5.14.1

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64326 : Information Disclosure in Weblate Localization Tool Vulnerability