PT-2026-3302 · Wlc+1 · Wlc+1

Zee99Y

·

Published

2026-01-01

·

Updated

2026-02-18

·

CVE-2026-23535

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weblate wlc versions prior to 1.17.2
Description The Weblate command-line client (wlc), which uses Weblate's REST API, is susceptible to an arbitrary file write issue. A crafted server can instruct the multi-translation download functionality to write files to an unintended location. This is due to unsanitized API slugs. The issue allows a malicious or compromised Weblate server to write arbitrary files to the client system. The vulnerability is related to the wlc download command.
Recommendations Versions prior to 1.17.2 should be updated to version 1.17.2. As a workaround, avoid using the wlc download command with untrusted servers.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-23535
GHSA-MMWX-79F6-67JG

Affected Products

Weblate
Wlc