Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Moderate severity
GitHub Reviewed
Published
Feb 26, 2026
in
WeblateOrg/weblate
•
Updated Feb 27, 2026
Description
Published to the GitHub Advisory Database
Feb 26, 2026
Reviewed
Feb 26, 2026
Published by the National Vulnerability Database
Feb 26, 2026
Last updated
Feb 27, 2026
Impact
Users were able to obtain add-on configuration via API.
Patches
References
Weblate thanks @lighthousekeeper1212 for responsible disclosure.
References