CVE-2025-67715: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-67715 is an improper access control vulnerability in Weblate, a web-based localization tool, that allows authenticated low-privileged users to enumerate all users or retrieve user notification settings via the REST API. It affects all Weblate versions prior to 5.15 and was disclosed on December 15, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Github Advisory, Weblate Advisory).

Technical details

The root cause is insufficient authorization enforcement in Weblate's REST API endpoints, classified as CWE-284 (Improper Access Control) and CWE-285 (Improper Authorization). The API failed to properly restrict user search results to authenticated users and did not enforce access controls on the user notification settings endpoint, allowing any authenticated user to query these resources regardless of their privilege level. The fix, implemented in pull request #17256, introduced an allow_self parameter to permission checks, restricted user search to authenticated users only, and enforced proper authorization on notification endpoints (Weblate PR #17256, Github Advisory).

Impact

Successful exploitation allows any authenticated user with low privileges to enumerate all user accounts registered in the Weblate instance and access notification settings for arbitrary users. This exposes usernames, account metadata, and notification preferences, which can be leveraged for targeted phishing, credential stuffing, or reconnaissance in preparation for further attacks. There is no integrity or availability impact; the vulnerability is limited to confidentiality (Weblate Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (2nd percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a valid (low-privilege) account on the target Weblate instance (Github Advisory).

Exploitation steps

  1. Obtain a low-privilege account: Register or obtain credentials for any valid user account on the target Weblate instance (no admin privileges required).
  2. Authenticate to the API: Use the Weblate REST API with the obtained credentials, e.g., via an API token or session cookie: curl -H "Authorization: Token <your_token>" https://<weblate-host>/api/users/
  3. Enumerate all users: Send a GET request to the /api/users/ endpoint. In vulnerable versions, the response returns a list of all registered users regardless of the requester's privilege level.
  4. Access notification settings: Send a GET request to /api/users/<username>/notifications/ for any user to retrieve their notification configuration, which may reveal additional account details.
  5. Use gathered data for reconnaissance: Compile the enumerated usernames and notification settings to identify high-value targets (e.g., administrators) for follow-on attacks such as phishing or credential stuffing (Weblate Advisory, Weblate PR #17256).

Indicators of compromise

  • Network: Repeated or automated GET requests to /api/users/ or /api/users/<username>/notifications/ from a single authenticated user or IP address, especially iterating over multiple usernames.
  • Logs: Weblate API access logs showing high-frequency enumeration of the /api/users/ endpoint by a low-privilege account; requests to notification endpoints for users other than the requester.
  • Behavior: A single user account making API calls to list all users or access notification settings for many different usernames in a short time window.

Mitigation and workarounds

Upgrade Weblate to version 5.15 or later, which enforces proper authorization on the user listing and notification settings API endpoints. No configuration-based workaround is available for unpatched versions; upgrading is the only effective remediation. As an interim measure, administrators should review API access logs for unusual enumeration activity and consider restricting API access to trusted networks where feasible (Weblate Advisory, Weblate PR #17256).

Community reactions

The vulnerability was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI, and the Weblate maintainer (nijel) promptly addressed it with a patch merged on December 10, 2025, ahead of the public advisory on December 15, 2025. No significant broader media coverage or notable community debate has been observed beyond the standard advisory publication (Weblate Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management