libretranslate@1.8.3

Free and Open Source Machine Translation API. Self-hosted, no limits, no ties to proprietary services.

  • latest version

    1.9.6

  • first published

    5 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the libretranslate package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Use of Less Trusted Source

    libretranslate is a Free and Open Source Machine Translation API. Self-hosted, no limits, no ties to proprietary services.

    Affected versions of this package are vulnerable to Use of Less Trusted Source via the get_remote_address function. An attacker can bypass per-IP rate limiting and flood bans by injecting arbitrary values into the X-Forwarded-For header without trusted proxy validation, enabling unlimited API abuse.

    How to fix Use of Less Trusted Source?

    A fix was pushed into the master branch but not yet published.

    [0,)