PT-2026-33116 · Weblate · Weblate
CVE-2026-33435
·
Published
2026-04-15
·
Updated
2026-04-16
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 5.17
Description
Project backup fails to filter Git and Mercurial configuration files, which could lead to remote code execution under certain circumstances.
Recommendations
Update to version 5.17.
Restrict access to the project backup to limit the scope of the issue, as this feature is only accessible to users with project creation privileges.
Exploit
Fix
Relative Path Traversal
Unrestricted File Upload
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate