Exposure of personal IP address via Email
Program: Weblate
Bug Type: PII Exposure
Bounty: Unspecified
Date: 2025-07-16
PII-Exposure
privacy-violation
sensitive-data
Summary
Weblate is an opensource translation integration software that translates documentations, and various commuication. When Weblate sends an email for various reasons such as notifications, password reset, etc. They include the Public IP address of the user doing the action. This passes through many smtp servers in the middle, storing information. Violating GDPR as Public IP is a PII. Impact is that exposed IP can be used for various attcks and recon.