PT-2025-25575 · Weblate · Weblate

Micael1

·

Published

2025-06-16

·

Updated

2025-07-16

·

CVE-2025-49134

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.12
Description The issue concerns the inclusion of the full IP address of the acting user in audit log notifications. This information could be obtained by third-party servers, such as SMTP relays or spam filters.
Recommendations For versions prior to 5.12, update to version 5.12 to resolve the issue. As a temporary workaround, consider restricting access to audit log notifications to minimize the risk of IP address exposure.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-49134
GHSA-4QQF-9M5C-W2C5

Affected Products

Weblate