The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.
Blocking access to /api/memory/ in the HTTP server removes access to this feature.
This issue was reported by ggamno via HackerOne.
{
"github_reviewed_at": "2026-04-16T20:41:19Z",
"nvd_published_at": "2026-04-15T18:17:20Z",
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": true
}