Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqph-7h49-hqfm

Опубликовано: 16 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository

Impact

The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.

Patches

Workarounds

The CDN add-on is not enabled by default.

References

Thanks to @spbavarva for reporting this responsibly via GitHub.

Пакеты

Наименование

Weblate

pip
Затронутые версииВерсия исправления

< 5.17

5.17

EPSS

Процентиль: 25%
0.00323
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-200
CWE-22

Связанные уязвимости

CVSS3: 6.8
nvd
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.

CVSS3: 6.8
debian
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, t ...

EPSS

Процентиль: 25%
0.00323
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-200
CWE-22