PT-2026-3302 · Wlc+1 · Wlc+1
Zee99Y
·
Published
2026-01-01
·
Updated
2026-02-18
·
CVE-2026-23535
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Weblate wlc versions prior to 1.17.2
Description
The Weblate command-line client (wlc), which uses Weblate's REST API, is susceptible to an arbitrary file write issue. A crafted server can instruct the multi-translation download functionality to write files to an unintended location. This is due to unsanitized API slugs. The issue allows a malicious or compromised Weblate server to write arbitrary files to the client system. The vulnerability is related to the
wlc download command.Recommendations
Versions prior to 1.17.2 should be updated to version 1.17.2.
As a workaround, avoid using the
wlc download command with untrusted servers.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblate
Wlc