weblate is vulnerable to Improper Authorization
53
Medium Risk
Weblate restores project backups without enforcing the component edit permission check applied by the normal interface. An authenticated user who can import backups can craft one containing a weblate:// repository link that points to a component they cannot access. The imported component then shares the private target's checkout, letting the user read private source strings and translations and commit changes that may be pushed to the victim's upstream repository. The fix resolves internal repository links using the importing user's permissions and skips inaccessible or invalid linked repositories.
You are affected if you are using a version that falls within the vulnerable range and users can import project backups.
weblate is vulnerable to Improper Authorization in versions 4.14.0 - 2026.7.1.
Upgrade the weblate library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant