VDB

CVE-2025-32021

CVE-2025-32021 PUBLISHED CVSS 2.200000047683716 LOW

Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11.

EPSS 0.36% · 28.7th percentile

Risk Scores

CVSS 3.1
2.200000047683716
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.36%
28.7th percentile

Affected Products

VendorProductVersions
PyPIweblate0
weblateweblate0
WeblateOrgweblate< 5.11

Timeline

  • Jan 21, 1970 Security Advisory
  • Apr 15, 2025 CVE Published
  • Apr 16, 2025 EPSS Score
  • Apr 24, 2025 Coalition ESS Score
  • Apr 28, 2025 EPSS Score
  • Apr 30, 2025 Coalition ESS Score
  • May 11, 2025 EPSS Score
  • May 23, 2025 EPSS Score
  • Jun 5, 2025 EPSS Score
  • Jun 17, 2025 EPSS Score
  • Jun 29, 2025 EPSS Score
  • Jul 12, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›