Description
Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the backend fails to verify the permission scopes associated with the key, effectively bypassing permission checks entirely for some endpoints. It's important to note that this vulnerability only affects projects that have inadvertently exposed their API keys on the internet. Projects that have kept their API keys secure are not impacted. This issue is fixed in version 3.23.1.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-4f9j-4vh4-p85v
Patch x_refsource_misc
https://github.com/tolgee/tolgee-platform/pull/1818
Patch x_refsource_misc
https://github.com/tolgee/tolgee-platform/commit/4776cba67e7bb8c1b0259376e3e5fa3bb46e45c7
Release Notes x_refsource_misc
https://github.com/tolgee/tolgee-platform/releases/tag/v3.23.1
Scores
CVSS v3
8.1
EPSS
0.0013
EPSS Percentile
32.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (1)
tolgee/tolgee
3.14.0 - 3.23.1
Published
Jul 27, 2023
Tracked Since
Feb 18, 2026