Weblate-Bedrohungsmodell¶
Projekt: Weblate
Last reviewed for Weblate 2026.10.1 at commit af7a54c07c.
Date: 2026-09-24.
Status: Accepted, 2026-09-01.
Version binding: This model is versioned with Weblate releases. A report against Weblate version N is triaged against the model published for version N, not against the latest development branch. (maintainer)
Reporting cross-reference: Reports that violate a property Weblate claims in
Security properties Weblate provides are reported through SECURITY.md
and Schwachstellen und Umgang mit Vorfällen. Reports that fall under Out of scope or
Security properties Weblate does not provide can be closed by citing this
document unless this model routes them to VALID-HARDENING. (documented)
(source: Schwachstellen und Umgang mit Vorfällen)
Provenance legend: *(documented)* means the claim is stated in Weblate
documentation; *(maintainer)* means it was stated by a maintainer during
this threat-model process; *(inferred)* means it was reasoned from the
current project shape and needs maintainer confirmation.
Weblate is a Django-based web localization platform. It accepts work from browser users, API clients, project-scoped tokens, repository webhooks, VCS repositories, backup archives, background workers, and configured external services, then stores and synchronizes translation projects through a database, datastore, local filesystem repositories, and external code-hosting systems. (documented) (source: Weblate-Dokumentation, Weblates REST-API, Kontinuierliche Lokalisierung)
Scope and intended use¶
This model describes shared trust boundaries and security properties. Features within a component family follow its general guidance unless an explicit exception applies; the representative surfaces below are not an exhaustive feature inventory. (maintainer)
Komponentenfamilie |
Representative surface |
Outside-process effects |
Modellstatus |
|---|---|---|---|
Web-UI und REST-API |
Browseransichten, Formulare, Sitzungsendpunkte, Weblates REST-API |
Datenbank, Datenspeicher, E-Mail, Protokolle, hochgeladene Dateien |
In scope. (documented) (source: Weblates REST-API, Konfigurationsanweisungen) |
Authentifizierung, Sitzungen und Autorisierung |
Anmeldung, 2FA, SSO, Teams, Berechtigungen, Projektzugriff, API-Token |
Datenbank, Identitätsanbieter, Browser-Cookies |
In scope. (documented) (source: Authentifizierung, Zugriffssteuerung) |
Projektbezogene API-Token |
Tokens created in project API access |
Same application effects as the token permissions allow |
In scope as authenticated actors with delegated project scope. (documented) (source: Weblates REST-API, Zugriffssteuerung) |
Webhooks |
Benachrichtigungs-Hooks, Projekt-Hooks aktivieren, App-Webhook-URL |
Hintergrundaufgabenplanung und VCS-Repository-Aktualisierungen |
In scope as a public, deployment-hardened interface. (documented) (source: Benachrichtigungs-Hooks, Hooks aktivieren, App-Webhook-URL) |
VCS-Integration |
Repository URLs, branches, pushes, pulls, merge requests, local clones, and GitHub App registration, connections, component migration, and removal |
Filesystem, child VCS commands, SSH/HTTPS network connections, and provider repository or installation state |
In scope when reachable through Weblate configuration or project content. (documented) (source: Kontinuierliche Lokalisierung, Code-Hosting-Integrationen) |
Hintergrundaufgaben |
Celery queues for repository updates, project deletion, notifications, translation memory, translation, and backups |
Datenbank, Datenspeicher, Dateisystem, Outbound-Netzwerk |
In scope as Weblate-controlled execution of user or operator actions. (documented) (source: Konfigurationsanweisungen, Weblates REST-API) |
Projektsicherung Import/Export |
Sicherungen auf Projektebene, Weblates REST-API-Projektsicherungsendpunkte, |
Hochgeladene ZIP-Archive, erzeugte Sicherungsarchive, Dateisystemwiederherstellung, Repository-Status |
In scope. (documented) (source: Weblate sichern und verschieben, Weblates REST-API, Verwaltungsbefehle) |
Dienstsicherung |
BorgBackup configuration and |
Local or remote backup storage over filesystem or SSH |
In scope for Weblate’s handling of configured backup jobs; Borg itself is out of scope. (documented) (source: Weblate sichern und verschieben, Verwaltungsbefehle) |
Maschinelle Übersetzung und ausgehende Integrationen |
Machine translation, avatars, status reporting, telemetry, error reporting, VCS hosts, GitHub App connections, CDN add-on, Fedora Messaging add-on, e-mail delivery (SMTP or AWS SES) |
Outbound HTTP(S), AMQP(S), provider APIs, logs |
In scope for Weblate’s enforcement of configured access and network restrictions. Provider behavior is out of scope. (documented) (source: Konfiguration, Code-Hosting-Integrationen, Erweiterungen) |
Erweiterungen |
Built-in add-ons and administrator-configured add-on execution |
Varies by add-on; can mutate project or repository state or contact services |
Built-in add-ons are in scope when enabled. Third-party add-ons are out of scope except for Weblate’s permission and installation gates. (maintainer) |
Verwaltungsbefehle |
weblate commands run by an operator |
Datenbank, Dateisystem, VCS, Sicherungsspeicher |
In scope when processing untrusted Weblate data; the local operator shell is trusted. (maintainer) |
Tests, generated docs, screenshots, development fixtures |
|
Development-only files and generated artifacts |
Out of scope for product security claims. (maintainer) |
Development environments are not supported production deployments and do not provide security isolation from a malicious checkout or local user. (maintainer)
The intended deployment is a server-side Weblate installation behind a web server or reverse proxy, with a WSGI or ASGI application server, PostgreSQL database, datastore, Celery workers, a writable data directory, and optional outbound VCS, backup, identity-provider, and machine-translation integrations. (documented) (source: Konfigurationsanweisungen)
The relevant actors are split by trust level: unauthenticated clients, authenticated users, reviewers, project managers, administrators, project-scoped API tokens, webhook senders, external VCS providers, configured external services, and local operators. (documented) (source: Zugriffssteuerung, Weblates REST-API)
Weblate is not intended to be embedded as an in-process security library, used as a sandbox for untrusted code, or exposed without the deployment controls documented for production use. (maintainer)
Out of scope¶
The following are explicit non-goals for this model:
A compromised operating system account, container runtime, database server, datastore, reverse proxy, or administrator shell. Weblate runs inside those boundaries and does not claim to protect itself from an already-compromised host. (maintainer)
A malicious Weblate site administrator or local operator with unrestricted server access. Such an actor can change settings, credentials, data, or code. (maintainer)
Vulnerabilities in third-party dependencies as independent projects. General Django, Django REST framework, Python Social Auth, BorgBackup, VCS, database, and provider vulnerabilities are reported upstream unless the issue is in Weblate’s use of them. (documented) (source: Schwachstellen und Umgang mit Vorfällen)
Build and release hygiene, including action pinning, artifact signing, dependency freshness, and repository branch protection. These affect project operations but are not threat-model claims about Weblate runtime behavior. (maintainer)
General security of external VCS providers, identity providers, mail servers, machine-translation services, avatar services, CDN storage, or backup storage. Weblate models only its configured interactions with them. (maintainer)
User organizations‘ translation-supply-chain choices outside Weblate. Outsourced or crowdsourced translator risks are described separately in Lokalisierungs-Bedrohungsmodell. (documented) (source: Lokalisierungs-Bedrohungsmodell)
Third-party add-on code, local customization code, development fixtures, generated documentation output, test-only code, and demo or example data. (maintainer)
Vertrauensgrenzen und Datenfluss¶
Weblate’s primary trust boundary is the network-facing application surface: browser views, API endpoints, webhook endpoints, and upload endpoints accept data from less-trusted actors and translate it into database rows, local repository state, background tasks, outbound requests, and rendered UI. (maintainer)
Abgrenzung |
Trust transition |
|---|---|
Client-Browser/API-Client zu Weblate |
Untrusted or authenticated requests become permission-checked application actions. (documented) (source: Weblates REST-API, Zugriffssteuerung) |
Weblate to public CDN storage and clients |
Enabling CDN publication deliberately moves selected translations and public build identifiers and resource mappings outside project access controls, including translations from private components. Removing published origin files cannot revoke cached or downloaded copies. Preparation files in the CDN filesystem remain non-public only when the origin excludes the reserved staging directory as required by Lokalisierungs-CDN. (documented) (source: Kotlin-SDK-CDN) |
Weblate request process to repository Celery worker |
Permission-checked browser and API repository actions become queued work carrying the initiating user and affected repository scope. The worker reacquires the datastore reservation and rechecks the user’s current VCS permission on the current repository owner before mutation. The broker, datastore, and workers are trusted parts of the same Weblate instance. (maintainer) |
Webhook-Sender zu Weblate |
Public forge notifications can schedule repository synchronization
where hooks are enabled, matching components by exact repository URL
rather than host or path suffix fallback. Generic hook responses expose
match counts and, for updated components, project/component slugs and API
URLs, including for private projects and restricted components.
Components managed through an authenticated integration are excluded
from generic matching and diagnostics; currently this applies to the
GitHub App VCS backend. Registered GitHub App webhooks authenticate with
a per-app URL token and GitHub signature verification. Opt-in legacy
GitHub App deliveries to the generic GitHub webhook URL authenticate
with a separately configured secret. (documented) (source: Benachrichtigungs-Hooks,
Hooks aktivieren, Webhook-Ziele abgleichen,
App-Webhook-URL,
|
Weblate zu Datenbank/Datenspeicher |
Permission-checked application state becomes persistent data and queued work. (documented) (source: Konfigurationsanweisungen) |
Weblate zu lokalen VCS-Repositorys |
Project configuration and repository content drive filesystem and VCS operations. (documented) (source: Kontinuierliche Lokalisierung) |
Weblate zu externen Diensten |
Configured URLs, credentials, and provider settings drive outbound network connections. (documented) (source: Code-Hosting-Integrationen, Konfiguration) |
Projektsicherungarchive und Weblate-Dateisystem |
Uploaded ZIP members and metadata become restored project state; generated project backups are written to and read from local backup storage. (documented) (source: Weblate sichern und verschieben, Weblates REST-API, Sicherungen auf Projektebene) |
Voraussetzungen für die Erreichbarkeit:
A web UI or API finding is in model only when reachable by an unauthenticated client, authenticated user, or project-scoped token through documented routes, forms, or API endpoints. (maintainer)
An authorization finding is in model only when it crosses a documented permission, team, project, component, language, glossary, token, or site-wide boundary. (documented) (source: Zugriffssteuerung)
A webhook finding is in model only when a request can reach an enabled hook endpoint and affect repository update scheduling, task volume, or information returned to the caller beyond the documented matching diagnostics. (documented) (source: Benachrichtigungs-Hooks, Hooks aktivieren, Webhook-Ziele abgleichen)
A VCS finding is in model only when attacker-controlled or less-trusted repository data, branch names, URLs, file names, commit metadata, or project configuration can influence Weblate’s VCS operations. (maintainer)
A backup import finding is in model only when reachable from a project backup uploaded through Weblate or supplied to
import_projectbackup. (documented) (source: Sicherungen auf Projektebene,import_projectbackup)A backup export finding is in model only when reachable from documented project backup creation or download routes, including the REST API for users or project-scoped tokens with project edit permission. (documented) (source: Weblates REST-API, Sicherungen auf Projektebene, Zugriffssteuerung)
A background-task finding is in model only when the task can be queued from an in-scope Weblate surface or scheduled Weblate maintenance path. (documented) (source: Konfigurationsanweisungen)
A management-command finding is in model only when untrusted Weblate data is processed by the command; arbitrary local shell access is not an attacker capability. (maintainer)
Umgebungsvoraussetzungen¶
Weblate assumes a supported Python and Django runtime, a correctly configured database, a datastore, a writable data directory, and running workers for features that require background processing. (documented) (source: Konfigurationsanweisungen)
Production deployments are expected to configure the external web server or
reverse proxy consistently with Weblate’s HTTPS, host header, body-size, and
proxy-header settings. (documented) (source: Konfigurationsanweisungen,
ENABLE_HTTPS, ALLOWED_HOSTS)
The database, datastore, and internal service ports are assumed not to be directly exposed to untrusted networks. (maintainer)
Filesystem permissions are assumed to prevent unrelated local users from modifying Weblate’s data directory, configuration, VCS repositories, generated SSH wrappers, backups, and secret material. (documented) (source: Weblate sichern und verschieben, Konfigurationsanweisungen)
Celery workers are trusted components of the same Weblate instance. A malicious or compromised worker is equivalent to a compromised application process. (maintainer)
Worker process and queue separation do not create security isolation; workers retain the same trusted application authority. (maintainer)
VCS command execution, SSH, and HTTPS clients are assumed to execute as the
Weblate service user with the credentials configured for the relevant project
or integration, including database-stored GitHub App credentials used for
installation tokens and webhook signature verification. (documented) (source: Code-Hosting-Integrationen,
SSH_EXTRA_ARGS)
Was Weblate mit seinem Host macht:
It opens outbound network connections for configured VCS, identity-provider, avatar, machine-translation, backup, status-reporting, telemetry, error-reporting, and add-on features such as outbound webhooks and Fedora Messaging AMQP delivery. (documented) (source: Konfiguration, Code-Hosting-Integrationen, Weblate sichern und verschieben)
It runs VCS and backup-related helper commands as part of repository and backup workflows. (documented) (source: Kontinuierliche Lokalisierung, Weblate sichern und verschieben)
It writes to the configured data directory, repository storage, media/fonts, backup dumps, logs, and cache locations. (documented) (source: Konfiguration, Weblate sichern und verschieben)
It sends e-mail and notifications through configured providers. Operator-controlled service endpoints and credentials are trusted infrastructure, outside user-configurable private-target restrictions. (documented) (source: Konfiguration, Installation über Docker)
It does not claim to be free of process-wide side effects such as logging, cache writes, subprocess execution, or outbound network access. (maintainer)
Build-Zeit und Konfigurationsvarianten¶
Knob |
Default or documented posture |
Auswirkungen auf das Modell |
Maintainer stance |
|---|---|---|---|
Anonymous remote hooks are configurable and must also be enabled for a project. (documented) |
Exposes webhook endpoints as a public scheduling interface. Abuse resistance depends on deployment controls. (documented) (source: Benachrichtigungs-Hooks, Hooks aktivieren) |
Production deployments exposing hooks use reverse-proxy rate limits, body-size limits, monitoring, and minimal public exposure. (maintainer) |
|
|
HTTPS affects secure cookies, redirects, HSTS, WebAuthn, and generated
URLs. (documented) (source: |
Disabling or misconfiguring HTTPS removes transport and cookie
protections that Weblate relies on for browser security. (documented) (source: |
The documented production posture is HTTPS with correct proxy headers. (documented) |
Konfiguriert akzeptierte HTTP-Hostnamen. (dokumentiert) (Quelle: |
Broad host acceptance can weaken host-header based protections and URL generation assumptions. (maintainer) |
Production deployments restrict this to instance hostnames. (maintainer) |
|
|
Rate limits are configurable. (documented) (source: Weblates REST-API, Konfiguration) |
Availability claims assume rate limits appropriate to deployment size and exposure. (maintainer) |
Operators can override or exempt users and IP networks, including
anonymous clients. IP exemptions rely on trusted proxy configuration;
they do not grant authentication or permissions. (documented)
(source: API-Ratenbegrenzung, |
|
Content Security Policy sources are configurable. (documented) (source: Konfiguration) The default script policy permits inline execution only on explicitly scoped compatibility paths. (maintainer) |
Broadening sources can reduce browser-side containment for XSS or third-party content. (maintainer) |
Deployments adding third-party sources accept that expanded browser trust. (maintainer) |
|
Defaults bound project backup upload and import size, member count, and suspicious compression ratios. (documented) (source: Konfiguration) |
Raising or disabling these limits expands restore-time resource exposure. (documented) (source: Konfiguration) |
The defaults documented above are part of backup-import resource guarantees. (documented) |
Private-target restrictions and allowlists for outbound URLs |
User-configurable outbound URL surfaces documented with private-target
restriction settings reject internal or non-public targets by default.
(documented)
(source: |
Allowlist settings and privileged configuration can intentionally expand
reachability. A non-empty |
Default private-target rejection is an application-level security property for the documented user-configurable URL surfaces. (maintainer) |
Ermöglicht benutzerdefinierte SSH-Optionen. (dokumentiert) (Quelle: |
Weakening SSH algorithms or host verification changes VCS transport assumptions. Routing options can override protected repository address pinning. (maintainer) |
Operators own the security impact of custom SSH options. (maintainer) |
|
Third-party add-ons and local customization |
Administrators can extend behavior. (documented) (source: Erweiterungen) |
Custom code can add new trust boundaries and security properties outside this model. (maintainer) |
Third-party code is modeled separately. (maintainer) |
Declarative automation expressions |
Add-on managers configure ordered Weblate operations and CEL conditions. (documented) (source: Arbeitsablauf-Definition) |
Expressions receive JSON context rather than application objects. A resource-limited helper process parses and evaluates CEL without custom function bindings; workflows cannot supply Python code. This is a distinct expression-evaluation boundary, not a sandbox for arbitrary Python. On macOS, the helper enforces CPU and wall-time limits but no memory cap, so expressions can exhaust memory within those time limits. (maintainer) |
Existing add-on management authority governs mutations. Operation scopes, validation, and automation-origin suppression constrain declarative runs; custom Python add-ons retain their separate trust model. (maintainer) |
Eingangsvoraussetzungen¶
Oberfläche |
Eingang |
Attacker-controllable? |
Aufrufender oder Betreiber muss erzwingen |
|---|---|---|---|
Browser-Formulare und REST-API |
Request bodies, query strings, uploaded files, headers, cookies |
Yes, within the actor’s authentication state. (documented) (source: Weblates REST-API) |
HTTPS, correct host/proxy configuration, rate limits, and permission assignment. (documented) (source: Konfigurationsanweisungen, Zugriffssteuerung) |
Authentifizierungs-Endpunkte |
Passwords, WebAuthn data, SSO callbacks, reset tokens |
Yes. (documented) (source: Authentifizierung) |
Correct identity-provider configuration and HTTPS. (documented) (source: Authentifizierung, |
Projektbezogene Token |
API-Anfragen authentifiziert durch Token |
Yes, by whoever holds the token. (documented) (source: Weblates REST-API) |
Token storage, rotation, and least-privilege team membership. (maintainer) |
Übersetzungsinhalt |
Ausgangszeichenketten, Übersetzungen, Kommentare, Übersetzungsvorschläge, Glossareinträge |
Yes, from users with relevant permissions or imported repositories. (documented) (source: Mit Weblate übersetzen, Zugriffssteuerung) |
Review workflows and permission assignment for project-specific content integrity. (documented) (source: Übersetzungsabläufe, Zugriffssteuerung) |
Webhook-Endpunkte |
Headers, event type, body, repository and branch metadata |
Yes, where endpoint is reachable. (documented) (source: Benachrichtigungs-Hooks) |
Hook enablement only where needed, request limits, and monitoring. (maintainer) |
GitHub App lifecycle |
Registration and installation callbacks, GitHub OAuth code, signed Weblate state, installation ID, account metadata, component migration selections, and connection-removal requests |
Yes, from authenticated Weblate users and GitHub redirect query strings. (documented) (source: GitHub-App über Weblate registrieren, Bestehende Komponenten migrieren) |
Registering App credentials requires the site-wide
|
Repository-Konfiguration |
Repository URLs, branches, push URLs, credentials, Gerrit review push options, add-on settings, and Versionsverwaltungs-Parameter controlling force pushes and pull-request behavior |
Trusted to users with corresponding management permissions. (documented) (source: Zugriffssteuerung, Kontinuierliche Lokalisierung) The automatic translation add-on can create approved strings when the target language’s effective review settings allow it. Configuring this behavior uses add-on management permissions rather than the configuring user’s review permission. (documented) (source: Erweiterungen) |
Assign VCS and project management permissions only to trusted users. (documented) (source: Zugriffssteuerung) |
Externer Repository-Inhalt |
Translation files, paths, branch names, commit metadata |
Yes, if the upstream repository is controlled by another actor. (maintainer) |
Trust the configured upstream repository or review imported changes. (maintainer) |
Projektsicherungsimport |
ZIP archive members, metadata, translation files, repository state |
Yes, for whoever can upload or provide the backup. (documented) (source: Sicherungen auf Projektebene) |
Keep import limits at values appropriate for the instance. (documented) (source: Konfiguration) |
Projektsicherungsexport |
Backup creation requests and requested backup file names |
Yes, for users or project-scoped tokens with project edit permission. (documented) (source: Weblates REST-API, Sicherungen auf Projektebene, Zugriffssteuerung) |
Grant project edit permission only to trusted project administrators. (documented) (source: Zugriffssteuerung) |
Maschinelle Übersetzung und externe Dienstkonfiguration |
Provider URLs, credentials, model or service settings |
Trusted to administrators or users granted configuration permissions. (documented) (source: Automatische Vorschläge, Zugriffssteuerung) |
Treat configured providers as recipients of the data sent to them; the submitted content varies by provider and enabled feature. (maintainer) |
Verwaltungsbefehle |
Command-line arguments and files supplied by the local operator |
Trusted local input unless processing Weblate data or project backups. (maintainer) |
Restrict shell access to trusted operators. (maintainer) |
Deployment configuration |
Environment variables, container arguments, mounted configuration, image selection, and workload or orchestration manifests |
Trusted local-operator input. Systems that delegate selected deployment values to less-trusted users introduce an external trust boundary; Weblate does not treat those values as untrusted application input. (maintainer) |
Restrict deployment access to trusted operators and validate delegated values before they reach Weblate. (maintainer) |
Size and rate assumptions:
Weblate relies on application and reverse-proxy upload limits for large HTTP requests. (documented) (source:
PROJECT_BACKUP_UPLOAD_MAX_SIZE)Project backup imports are bounded by member count, aggregate uncompressed size, compressed entry size, minimum ratio size, and compression ratio settings. (documented) (source: Konfiguration)
Project backup metadata, object references, repository paths, outbound URLs, regular expressions, and screenshot content are validated before restore writes project state. Failed restores remove repository and media objects created by that attempt. (documented) (source: Sicherungen auf Projektebene)
API and selected web actions are expected to be protected by configured rate limits. (documented) (source: Weblates REST-API, Konfiguration)
Repository size, number of projects, number of components, and worker capacity are deployment-sizing concerns unless a single in-scope input bypasses documented limits or permissions. (maintainer)
Adversary model¶
Actor |
In-scope capabilities |
Out-of-scope capabilities |
|---|---|---|
Nicht authentifizierter Internet-Client |
Send HTTP(S) requests to public pages, registration, login, API, and reachable webhook endpoints. (documented) (source: Weblates REST-API) |
Read server memory, bypass reverse proxy controls, or access internal services directly. (maintainer) |
Authentifizierter Benutzer |
Perform actions allowed by assigned teams, permissions, and workflow. (documented) (source: Zugriffssteuerung) |
Act outside assigned permissions without exploiting a Weblate flaw. (documented) (source: Zugriffssteuerung) |
Prüfer oder Projektmanager |
Exercise delegated project, component, language, review, VCS, translation memory, screenshot, or access-management permissions. (documented) (source: Zugriffssteuerung) |
Become a site administrator unless granted that role or exploiting a Weblate flaw. (maintainer) |
Project-scoped API token holder |
Use API permissions assigned to the token’s team memberships, including project backup creation and download where project edit permission is granted. (documented) (source: Weblates REST-API, Zugriffssteuerung, Sicherungen auf Projektebene) |
Access projects, components, or site-wide functions outside its scope. (documented) (source: Zugriffssteuerung) |
Webhook-Sender |
Send forged, replayed, malformed, or high-volume webhook requests to enabled hook endpoints and observe documented matching diagnostics. (documented) (source: Benachrichtigungs-Hooks, Webhook-Ziele abgleichen) |
Obtain forge-authenticated identity where Weblate does not verify it. (maintainer) |
External VCS or service provider |
Return repository data, API responses, redirects, or errors according to the configured integration. (documented) (source: Code-Hosting-Integrationen) |
Compromise the Weblate host except through data or protocol behavior Weblate processes. (maintainer) |
Übersetzer oder Mitwirkender bei der Lokalisierung |
Submit translation content that downstream applications might consume. (documented) (source: Lokalisierungs-Bedrohungsmodell) |
Control downstream application escaping, rendering, or review policy outside Weblate. (documented) (source: Lokalisierungs-Bedrohungsmodell) |
Lokaler Betreiber |
Run management commands, change configuration, and access backups. (documented) (source: Verwaltungsbefehle, Weblate sichern und verschieben) |
Local malicious operators are trusted for this model. (maintainer) |
The modeled attacker tries to bypass authorization, modify translation or repository data without permission, disclose private project or user data, forge or abuse repository synchronization, trigger unsafe outbound requests, execute commands through Weblate-controlled workflows, or exhaust bounded application resources. (maintainer)
Sicherheitseigenschaften, die Weblate bereitstellt¶
Property |
Conditions |
Violation symptom |
Schweregrad |
|---|---|---|---|
Web authorization separates site, project, component, language, glossary, VCS, translation memory, screenshot, review, and access management permissions. (documented) (source: Zugriffssteuerung, Authentifizierung, Übersetzungsspeicher) |
Permission assignments match the intended trust relationship.
Team-level enforced 2FA is satisfied by human users before
team-derived permissions apply. Pending authenticator app registrations
do not satisfy 2FA requirements. Registration requires a valid,
single-use TOTP code and cannot be completed more than once, including
under concurrent submissions. (documented) (source: Zwei-Faktor-Authentifizierung)
Component administrators are trusted to
configure operations that can affect repository contents, for example by
selecting files through component settings, configuring add-ons, or
enabling force pushes and pull-request behavior through Versionsverwaltungs-Parameter.
Add-ons are persistent administrative configuration: project and category
add-ons operate on compatible restricted descendants, while component
add-ons can consume cross-component inputs documented by the add-on.
Their service identities and configured authority do not depend on the
configuring user’s later account or permission state. Project backups
similarly contain every component in the project, including restricted
components. Consequently, component restrictions protect ordinary direct
access but are not an isolation boundary against these documented
administrative capabilities.
Users with management rights for a workspace are trusted to connect and
remove its GitHub App installations; removing the final workspace
connection can uninstall the App from GitHub. GitHub App component
migration separately requires edit permission for every selected
component.
Linking a repository extends this trust to administrators of every
linked component for the complete shared checkout. Permissions for
explicit VCS actions are checked on the repository-owning component.
Linking accepts this owner’s authority over the complete shared checkout;
permissions on downstream linked components neither grant nor veto
explicit VCS authority. Project-wide
VCS actions omit repositories where this permission check fails; they do
not partially operate on an individual shared checkout. Explicit VCS
actions queued from the browser or API retain the initiating user,
serialize access to the affected repositories, and recheck that user’s
permission on the current repository owner in the worker
before mutation. Weblate’s normal background commit and push of
authorized translation changes does not require the editor to have
these VCS permissions. The |
User or token can read or mutate data outside assigned scope. |
Security-critical when private data or privileged mutation is exposed. |
Project-scoped API tokens are limited by assigned project/team permissions. (documented) (source: Weblates REST-API, Zugriffssteuerung) |
Token is created and stored by a trusted actor. |
Token can act outside project or team scope. |
Sicherheitskritisch. |
Authentication and session controls protect browser sessions when HTTPS
and proxy settings are correct. Pending second-factor sessions are bound
to the current password authentication state, and repeated rejected
second-factor submissions lock password sign-in according to
|
Production HTTPS and secure-cookie settings are enabled. |
Session fixation, credential bypass, cross-user session confusion, or a pending password sign-in remaining usable after a password change or account lock. |
Sicherheitskritisch. |
User-supplied content rendered by Weblate is expected not to execute script in other users‘ browsers. (maintainer) |
Content is displayed through Weblate UI templates and standard escaping. |
Stored or reflected XSS in the Weblate origin. |
Sicherheitskritisch. |
Repository, branch, path, and VCS inputs processed by Weblate must not become shell command execution. (maintainer) |
VCS operations are invoked through Weblate-supported repository workflows and configured credentials. Project backup restores allow only non-executable Git, git-svn, and Mercurial repository state, and rebuild repository-local configuration from validated component settings. Weblate does not populate Git submodules (see Git-Submodule). |
Command injection or arbitrary code execution as the Weblate user. |
Sicherheitskritisch. |
Private project data other than documented generic webhook matching diagnostics, metadata published through Öffentliche Freigabe, and translations, build identifiers, and resource mappings explicitly published through CDN add-ons, user data, credentials, tokens, SSH keys, and 2FA secrets are not disclosed to actors lacking permission. (documented) (source: Zugriffssteuerung, Einhaltung der Datenschutzrichtlinien, Integration der Versionsverwaltung) |
Host, database, and storage permissions are intact. Generic webhook responses expose only the match counts, project/component slugs, and API URLs documented in Webhook-Ziele abgleichen. Public sharing permits unauthenticated access to engage pages and rendered status widgets, exposing project and component names, including restricted components, translation statistics, languages, and progress. It does not grant access to project content or APIs. Repository content deliberately shared through linked components follows the linked repository trust boundary. Project repository permission diagnostics identify accessible repository owners where an operation requires permission, but do not expose inaccessible component identities or blocked repository content or status. Custom add-ons list only non-sensitive fields as public configuration; unlisted values are redacted from public change history. Installing the Kotlin-SDK-CDN add-on explicitly publishes translations, application package names and version codes, and the names and submitted IDs of published resources from that component to unauthenticated CDN clients, including for private projects. CDN storage and cached client copies are outside project access controls; removing origin files cannot revoke previously downloaded copies. |
Cross-project data leak not covered by the documented generic webhook diagnostics, public-sharing metadata, explicit CDN publication, or linked-repository trust boundary, credential exposure, or unauthorized export. |
Sicherheitskritisch. |
Backup import rejects archives exceeding documented upload, member, aggregate size, and suspicious compression thresholds. (documented) (source: Konfiguration, Sicherungen auf Projektebene) |
Defaults or stricter limits remain configured. |
Oversized or highly amplified archive is accepted past configured thresholds. |
Security-critical for single-request DoS; otherwise availability bug. |
Documented user-configurable outbound URL surfaces reject internal or
non-public targets by default. (documented) (source:
|
Default private-target checks are enabled and no trusted allowlist exemption applies. Direct protected HTTP requests and Git HTTPS and SSH operations retain address binding, VCS restrictions remain enabled, and VCS backends without binding use only explicitly trusted hosts. Configured per-protocol HTTP proxies remain trusted routing infrastructure. |
A user-configurable screenshot URL, remote HTML URL, project website or repository browser URL, outbound webhook URL, or VCS URL reaches an internal or non-public target despite default controls. |
Security-critical when it exposes internal services or metadata. |
Weblate records security-relevant account, permission, billing lifecycle,
authenticated web-action rate-limit lockouts, and project or component
setting changes in audit logs or history. Account-removal audit entries
retain the former e-mail address until |
Logging is configured, storage is available, and
|
Missing audit trail for an action Weblate claims to log, or personal data retained beyond the configured audit-log expiry. |
Security-critical when it blocks investigation of privileged changes or discloses retained personal data; privacy-impacting when data exceeds the configured retention; correctness-only for minor event gaps. |
Self-service trial creation grants only the designated commercial trial plan or the Libre setup plan. (maintainer) |
The deployment offers self-service hosting trials. |
An authenticated user can select another public, private, or internal billing plan when creating a trial. |
Security-critical when this bypasses paid service limits. |
Rate-limited API and web actions enforce configured rate limits. (documented) (source: Weblates REST-API, Konfiguration) |
Rate limiting is enabled and backed by a working datastore. |
Requests exceeding configured thresholds continue to be processed. |
Availability/security hardening depending on endpoint sensitivity. |
Built-in translation quality checks must not permit user-controlled content within configured size limits to monopolize synchronous request workers through disproportionate resource consumption. (maintainer) |
The check is enabled and runs during a supported browser or API translation write. |
A single accepted translation causes CPU or memory consumption disproportionate to its size and stalls a request worker. |
Security-critical for single-request DoS; otherwise availability bug. |
Generic webhooks schedule repository updates only for eligible components whose repository URL exactly matches a repository URL from the payload, including documented URL variants. Components managed through an authenticated integration are excluded from generic matching and diagnostics. Generic responses disclose only the documented matching diagnostics for eligible components. (documented) (source: Webhook-Ziele abgleichen) |
Hooks are enabled and the delivery reaches an in-scope hook endpoint. |
A delivery updates a component whose repository URL does not exactly match the payload, including through host or path suffix fallback, or a generic delivery updates or discloses a component managed through an authenticated integration, or a response discloses component information beyond the documented fields. |
Security-critical when it causes unauthorized repository synchronization across unrelated components; otherwise correctness or hardening. |
Weblate does not intentionally expose database, datastore, backup storage, or raw internal storage directly through the public web interface; exported VCS repositories are intentionally exposed by Git-Exporter when that optional module is enabled; authorized project backup downloads are intentionally exposed through documented project backup routes. (documented) (source: Weblates REST-API, Sicherungen auf Projektebene) (maintainer) |
Deployment does not serve internal storage paths as static files except for documented export features. |
Public request retrieves raw internal storage, configuration, or non-exported repository data. |
Sicherheitskritisch. |
Resource thresholds in this model are the documented configuration defaults where they exist, especially backup import limits and rate limits. For repository size, project count, component count, and translation volume, Weblate does not claim a fixed universal resource ceiling independent of deployment capacity. (maintainer)
Component discovery bounds repository traversal and file-mask matching work even when repository content controls the masks; see component discovery limits. (maintainer)
Security properties Weblate does not provide¶
Weblate does not authenticate every webhook delivery cryptographically for all
supported forge integrations. Hook endpoints are compatibility-oriented and
deployment-hardened rather than uniformly forge-authenticated. Reports that
show only unauthenticated triggering within modeled effects are
VALID-HARDENING rather than BY-DESIGN. (maintainer)
Weblate does not make an unauthenticated webhook equivalent to a trusted forge identity. Hook processing can trigger update workflows, and generic responses can confirm repository registration and reveal match counts, project/component slugs, and API URLs, including for private projects and restricted components. Components managed through an authenticated integration are excluded from this generic behavior. Attribution and authenticity are weaker than for an authenticated user or token. (maintainer)
User-requested background work is authorized when Weblate accepts and queues the request. Background tasks do not always verify the initiating user’s permissions again when they execute. Later changes to the user’s account, permissions, or team memberships therefore do not reliably prevent already-authorized work from completing. (maintainer)
Weblate is not a sandbox for malicious administrators, malicious local operators, third-party add-ons, custom deployment code, VCS clients, or backup tools. (maintainer)
Weblate does not guarantee that translation content is safe when copied into a downstream product without that product’s own escaping, validation, or review. Translation checks and review workflows help manage localization quality and risk; they are not a complete downstream application security boundary. (documented) (source: Lokalisierungs-Bedrohungsmodell, Überprüfungen und Korrekturen)
False friends:
Weblate permissions are application authorization, not a host sandbox. A user granted VCS or project management permissions can intentionally configure integrations within that role’s power. (maintainer)
Webhook project matching and event parsing are not proof that the sender is the legitimate forge when the integration does not authenticate the delivery. (maintainer)
Translation checks detect common quality and format problems; they are not a guarantee that translated strings are safe for every downstream renderer. (documented) (source: Überprüfungen und Korrekturen, Lokalisierungs-Bedrohungsmodell)
BorgBackup encryption protects backup archives according to Borg’s design; Weblate does not add a separate cryptographic guarantee for Borg internals. (documented) (source: Weblate sichern und verschieben)
Rate limits reduce abuse of configured endpoints; they are not a guarantee of availability under volumetric network attacks. (maintainer)
Well-known attack classes left partly or wholly to deployment or downstream systems:
Phishing and credential reuse are mitigated by authentication policy and 2FA, but Weblate cannot prevent users from disclosing credentials outside the service. (maintainer)
Malicious translations can become XSS, format-string, command, or policy problems in downstream applications that render them unsafely. (documented) (source: Lokalisierungs-Bedrohungsmodell)
User-configurable outbound URL surfaces with documented private-target restrictions reject internal or non-public targets by default; privileged allowlists, proxies, and administrator-controlled configuration can intentionally expand reachability. (maintainer)
Large repository histories, project scale, and background task volume require deployment sizing and operational limits beyond Weblate’s single-input validation. (maintainer)
Downstream responsibilities¶
Operators must deploy Weblate behind production-grade HTTPS with correct proxy
headers, hostnames, request-size limits, and secure-cookie behavior.
(documented) (source: Konfigurationsanweisungen, ENABLE_HTTPS,
ALLOWED_HOSTS)
Operators enabling forwarded client-IP handling must trust only reverse proxies
under their control and prevent untrusted clients from bypassing those proxies
to reach Weblate directly. (documented) (source:
WEBLATE_TRUSTED_PROXY_ADDRESSES, Hinter einem Reverse-Proxy ausführen)
Operators must assign teams, roles, project-scoped tokens, VCS credentials, and project management permissions according to least privilege for their organization. (documented) (source: Zugriffssteuerung, Weblates REST-API)
Operators exposing Benachrichtigungs-Hooks must enable them only where needed and provide deployment controls such as reverse-proxy rate limits, body-size limits, monitoring, and optional source restrictions. They must accept the documented identifier disclosure or use authenticated integrations where available. (maintainer)
Operators must treat private-target allowlists, proxies, and privileged outbound integration settings as intentional expansion of Weblate’s default network reachability limits. (maintainer)
Operators must keep backup import limits, API rate limits, and web rate limits at values that match instance capacity and exposure. (documented) (source: Konfiguration)
Operators must protect the Weblate data directory, configuration, backup credentials, generated keys, database, datastore, and local shell access as trusted infrastructure. (documented) (source: Weblate sichern und verschieben, Konfigurationsanweisungen)
Downstream product teams must treat translated strings as untrusted content in their own applications unless they have separately reviewed, escaped, and validated them for the target renderer. (documented) (source: Lokalisierungs-Bedrohungsmodell)
Known misuse patterns¶
Exposing webhook endpoints broadly, enabling project hooks, and relying on webhook payloads as authenticated forge identity. This is unsafe because some supported hooks are compatibility-oriented and return matching diagnostics. Use deployment controls and prefer authenticated integrations where available. (maintainer)
Granting workspace, project, VCS, or access-management permissions to users who are trusted only as translators. This is unsafe because those permissions can affect code-hosting connections, repositories, credentials, or other users. Assign narrower roles. (documented) (source: Zugriffssteuerung, Code-Hosting-Integrationen)
Assigning site-wide permissions to roles intended for limited project or helpdesk delegation. Site-wide permissions apply across the instance and are not narrowed by the team’s project selection. In particular,
group.editpermits changing site-wide team scope and granting team members access to private projects the manager cannot access directly, whileuser.editpermits changing team memberships and superuser status for editable accounts, including the caller’s own account. Delegate permissions through project or workspace teams for limited scopes. (documented) (source: Zugriffssteuerung)Sending sensitive source strings or private customer content to machine translation providers without treating the provider as a data recipient. This is unsafe because Weblate must transmit content to the configured service, and the submitted content varies by provider and enabled feature. Configure providers according to the data policy for the project. (maintainer)
Importing project backups from untrusted sources as an administrative convenience. This is unsafe because backups carry project metadata, translation content, and repository state. Keep import limits enabled and import only backups appropriate for the target instance. (documented) (source: Weblate sichern und verschieben)
Treating Weblate translation checks as proof that downstream applications cannot be attacked through translated strings. This is unsafe because the downstream renderer defines the final execution context. Review and escape translations in the consuming application. (documented) (source: Lokalisierungs-Bedrohungsmodell)
Known non-findings¶
A report that a reachable webhook can be called without forge authentication and only triggers modeled update scheduling or returns the documented matching diagnostics is not
VALIDby itself. It is routed toVALID-HARDENINGunless it bypasses documented limits, matches unrelated repositories, leaks data beyond the documented fields, or causes effects beyond modeled scheduling. (maintainer)A report that a webhook does not update a component whose repository URL only shares a host or path suffix with the payload is not a vulnerability; Weblate matches only exact repository URLs and documented variants. (documented) (source: Webhook-Ziele abgleichen)
A report that a project manager can change repository settings, VCS credentials, or project configuration is not a vulnerability when the actor has the documented permission for that action. (documented) (source: Zugriffssteuerung)
A report containing private-project or restricted-component data is not a vulnerability when the user has effective
reports.viewpermission on the selected parent scope. That permission intentionally authorizes the complete report scope. (documented) (source: Übersetzungsberichte, Zugriffssteuerung)A report that a project administrator can obtain restricted descendants from a complete project backup, or that an add-on manager can configure a core add-on to process its documented restricted descendants or cross-component inputs, is not a vulnerability. These are persistent administrative capabilities and do not inherit the configuring user’s direct component visibility. (documented) (source: Erweiterungen, Sicherungen auf Projektebene, Zugriffssteuerung)
A report against third-party add-on behavior is not a Weblate core vulnerability unless the report shows Weblate’s permission or installation boundaries are bypassed. (maintainer)
A report that a malicious local operator can read configuration, run management commands, or alter files is out of model because local operators are trusted infrastructure. (maintainer)
A report that an operator-supplied environment variable, container argument, or mounted configuration can alter generated service configuration is not a vulnerability. These are trusted deployment inputs. A CI/CD, GitOps, PaaS, Helm, or other orchestration layer that lets less-trusted users set selected values owns that delegation boundary and must validate the values before constructing the Weblate workload. (maintainer)
A report that a downstream application renders a dangerous translation is not a Weblate vulnerability unless Weblate itself violates a claimed property while storing, checking, reviewing, or displaying that translation. (documented) (source: Lokalisierungs-Bedrohungsmodell)
Conditions that change this model¶
Review this model when changes affect public interfaces, authentication or authorization, deployment assumptions, untrusted input processing, external integrations, execution capabilities, or security-relevant defaults. Review whether the existing scope, actors, trust boundaries, assumptions, security properties, and triage dispositions still cover the change. (maintainer)
Revise this model in the same change only when those elements change or leave a gap. This includes an unsupported component becoming supported product surface, a claimed security property changing, or an accepted vulnerability report that cannot be routed to an existing triage disposition. (maintainer)
Features that follow existing boundaries and security properties do not need individual entries. Keep endpoint schemas, permission details, configuration instructions, implementation mechanics, and numeric limits in the relevant feature or administration documentation. Link to that documentation when a detail is needed to explain a distinct boundary, exception, or triage outcome. A review that confirms existing coverage requires no threat-model edit. (maintainer)
Triage dispositions¶
Disposition |
Bedeutung |
Lizenziert durch |
|---|---|---|
|
Violates a property Weblate claims, through an in-scope actor and input. |
Security properties Weblate provides, Input assumptions, Adversary model |
|
No claimed property is violated, but Weblate chooses to reduce a known misuse risk, such as compatibility webhook triggering that stays within modeled effects. |
Known misuse patterns, Security properties Weblate does not provide |
|
Requires attacker control of input this model marks trusted. |
|
|
Requires a capability this model excludes. |
|
|
Lands in third-party add-ons, generated docs, tests, local customization, or another component marked out of scope. |
|
|
Manifests only after deployment choices that knowingly remove a claimed property. |
|
|
Concerns a property Weblate explicitly does not provide. |
|
|
Matches a documented recurring false positive. |
|
|
Cannot be cleanly routed to any disposition above. |