Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 PyPI

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

GHSA-gcg5-86jr-f7jg · CVE-2026-44263

Published · Modified

Description

Impact

The screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user.

Patches

Acknowledgement

Weblate thanks Luay for reporting this vulnerability according to the organization's security issues guideline.

Ready to move

Start Securing

Free, no credit card | First findings in minutes