PT-2026-22201 · Weblate · Weblate
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 5.16.1
Description
Weblate’s REST API
AddonViewSet in weblate/api/views.py (line 2831) did not properly restrict access to addon information based on user permissions. Specifically, the queryset = Addon.objects.all() assignment within the viewset allowed any authenticated user, or even anonymous users if REQUIRE LOGIN was not enabled, to list all addons across all projects and components using the GET /api/addons/ and GET /api/addons/{id}/ API endpoints. This allowed unauthorized access to addon configurations.Recommendations
Update to Weblate version 5.16.1 or later.
Exploit
Fix
Information Disclosure
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate