Weblate has improper validation upon invitation acceptance
Description
Published to the GitHub Advisory Database
Dec 15, 2025
Reviewed
Dec 15, 2025
Published by the National Vulnerability Database
Dec 15, 2025
Last updated
Dec 17, 2025
Impact
It was possible to accept an invitation opened by a different Weblate user.
Patches
Workarounds
Users should avoid leaving Weblate sessions with an unattended opened invitation.
References
Thanks to Nahid0x for responsibly disclosing this vulnerability to Weblate.
References