CVE-2025-64326: Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit log
Summary Weblate leaks the IP address of the project member inviting the user to the project in the audit log.
Details The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.
Impact
The inviting user's (admin's) IP address could be leaked to invited users.
Other sources
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64326?
CVE-2025-64326 is considered a security vulnerability that exposes the inviting user's IP address in the audit log.
How do I fix CVE-2025-64326?
To remediate CVE-2025-64326, upgrade Weblate to version 5.14.1 or later.
What is the impact of CVE-2025-64326?
The impact of CVE-2025-64326 is that it allows invited users to view the IP address of the admin who invited them.
Who is affected by CVE-2025-64326?
CVE-2025-64326 affects users of Weblate versions prior to 5.14.1 who have admin roles that invite others to projects.
What components of Weblate are involved in CVE-2025-64326?
CVE-2025-64326 involves the audit log functionality of Weblate which improperly exposes IP addresses.