PatchSiren

LibreTranslate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM LibreTranslate CVE published 2026-09-16

CVE-2026-92803

CVE-2026-92803 debrief: LibreTranslate 1.9.6 download_file route has no access check, allowing unauthenticated file downloads. This CVE was published on 2026-09-16T21:17:29.970Z and was last modified on 2026-09-22T20:53:07.383Z. The vulnerability allows attackers to bypass API key requirements and abuse ban lists to download files without authentication on protected instances. Defenders should assess expo [truncated]