Skip to main content

Improper Removal of Sensitive Information Before Storage or Transfer

CVE-2025-64326

Severity Low
Score 3.5/10

Summary

Weblate is a web based localization tool. In versions through 5.14, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • LOW
  • LOW
  • NONE

CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Advisory Timeline

  • Published