PT-2026-33125 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-05-15

·

CVE-2026-40256

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description Repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This process is not path-segment aware and can be bypassed when an external path shares the same string prefix as the repository path, such as when one path is named repo and another is repo outside.
Recommendations Update to version 5.17.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-40256
GHSA-FFGH-3JRF-8WVH

Affected Products

Weblate