Description
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
References
https://github.com/WeblateOrg/weblate/pull/17516
Issue Tracking
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385
PatchVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-14T17:16:07.940Z
1 month agoLast modified
2026-01-23T14:49:52.287Z
4 weeks ago