VYPR

Libretranslate

by LibreTranslate

CVEs (2)

  • CVE-2026-92803MedSep 16, 2026
    risk 0.27cvss 5.3epss 0.01

    LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances.

  • CVE-2026-57942MedJun 29, 2026
    risk 0.00cvss 5.3epss 0.00

    LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary values into the X-Forwarded-For header without trusted…