PT-2026-94077 · Libretranslate+1 · Libretranslate
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreTranslate versions prior to 1.9.7
Description
The
download file route omits the access check decorator, which enables unauthenticated access to translated files. This allows attackers to bypass API key requirements and ignore ban lists to download files from protected instances.Recommendations
Update to version 1.9.7 or later.
As a temporary workaround, restrict access to the
download file route to minimize the risk of unauthorized file downloads.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libretranslate