weblate is vulnerable to Information Disclosure
53
Medium Risk
Weblate's object-scoped RSS feeds return change history metadata without applying the permission checks used by the equivalent API endpoints. Unauthorized and unauthenticated users can read change metadata from private projects and restricted components. Exposed data can include project and component identities, contributor usernames and names, action types, timestamps, and translation links. The fix applies Weblate's permission-aware change filtering to the feeds.
You are affected if you are using a version that falls within the vulnerable range and you host private projects or restricted components whose object-scoped RSS feeds are reachable by unauthorized users.
weblate is vulnerable to Information Disclosure in versions 0.0.1 - 2026.7.1.
Upgrade the weblate library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant