CVE-2025-32021

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 30, 2025
CWE ID 598

Summary

CVE-2025-32021 is a vulnerability affecting Weblate, a web-based localization tool. Before version 5.11, creating a new component from an existing one with a source code repository URL in settings resulted in the URL being included in client's URL parameters. If this URL contained GitHub credentials, the confidential PAT (Personal Access Token) and username were exposed in plaintext and saved in browser history. Furthermore, if using Weblate's official Docker image, nginx logs the URL and token in plaintext. This issue was patched in version 5.11.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share