PT-2026-3302 · Weblate+1 · Weblate+1

·

CVE-2026-23535

·

Published

2026-01-01

·

Updated

2026-07-07

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weblate wlc versions prior to 1.17.2
Description The Weblate command-line client (wlc), which uses Weblate's REST API, is susceptible to an arbitrary file write issue. A crafted server can instruct the multi-translation download functionality to write files to an unintended location. This is due to unsanitized API slugs. The issue allows a malicious or compromised Weblate server to write arbitrary files to the client system. The vulnerability is related to the wlc download command.
Recommendations Versions prior to 1.17.2 should be updated to version 1.17.2. As a workaround, avoid using the wlc download command with untrusted servers.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23535
GHSA-MMWX-79F6-67JG
PYSEC-2026-2053

Affected Products

Weblate
Wlc