PT-2026-33116 · Weblate · Weblate

CVE-2026-33435

·

Published

2026-04-15

·

Updated

2026-04-16

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description Project backup fails to filter Git and Mercurial configuration files, which could lead to remote code execution under certain circumstances.
Recommendations Update to version 5.17. Restrict access to the project backup to limit the scope of the issue, as this feature is only accessible to users with project creation privileges.

Exploit

Fix

Relative Path Traversal

Unrestricted File Upload

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33435
GHSA-558G-H753-6M33
PYSEC-2026-154

Affected Products

Weblate