PT-2026-33116 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-33435

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description Project backup fails to filter Git and Mercurial configuration files, which could lead to remote code execution under certain circumstances.
Recommendations Update to version 5.17. Restrict access to the project backup to limit the scope of the issue, as this feature is only accessible to users with project creation privileges.

Fix

Code Injection

Relative Path Traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-33435
GHSA-558G-H753-6M33
PYSEC-2026-154

Affected Products

Weblate