Published issues
Permalink
CVE-2026-33214
4.3 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): LOW
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate has improper access control for the translation memory API
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-33220
6.8 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): REQUIRED
-
Scope (S): CHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-40256
5.0 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). This issue has been fixed in version 5.17.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-33440
5.0 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-33435
8.1 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): HIGH
-
Privileges required (PR): HIGH
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): HIGH
-
Availability impact (A): HIGH
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python314Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-schemas
- python312Packages.weblate-schemas
- python314Packages.weblate-fonts
- python313Packages.weblate-fonts
- python312Packages.weblate-language-data
- python313Packages.weblate-schemas
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: Remote code execution during backup restoration
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-34244
5.0 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python314Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-schemas
- python312Packages.weblate-schemas
- python314Packages.weblate-fonts
- python313Packages.weblate-fonts
- python313Packages.weblate-schemas
- python312Packages.weblate-language-data
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: SSRF via Project-Level Machinery Configuration
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request to the attacker-controlled URL and reflects up to 200 characters of the response body back to the user in an error message. This constitutes a Server-Side Request Forgery (SSRF) with partial response read. This issue has been fixed in version 5.17. If developers are unable to immediately upgrade, they can limit available machinery services via WEBLATE_MACHINERY setting.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-34393
8.8 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): HIGH
-
Availability impact (A): HIGH
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python312Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python314Packages.weblate-language-data
- python313Packages.weblate-language-data
- python313Packages.weblate-schemas
- python314Packages.weblate-fonts
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: Privilege escalation in the user API endpoint
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-33212
3.1 LOW
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): HIGH
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python314Packages.weblate-language-data
- python313Packages.weblate-language-data
- python312Packages.weblate-language-data
- python314Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-fonts
- python313Packages.weblate-fonts
- python312Packages.weblate-schemas
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: Improper access control for pending tasks in API
Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of the task, so exploiting this is unlikely with the default API rate limits. This issue has been fixed in version 5.17.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-34242
7.7 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): NONE
-
Availability impact (A): NONE
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
18 hours ago
-
@LeSuisse
ignored
8 packages
- python314Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-schemas
- python313Packages.weblate-schemas
- python312Packages.weblate-schemas
- python314Packages.weblate-fonts
- python312Packages.weblate-language-data
- python313Packages.weblate-fonts
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate: Arbitrary File Read via Symlink
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (8)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate
Permalink
CVE-2026-24126
6.6 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): HIGH
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): LOW
-
Availability impact (A): LOW
updated 13 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
1 month, 4 weeks ago
-
@LeSuisse
ignored
6 packages
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
14 hours ago
-
@LeSuisse
accepted
14 hours ago
-
@LeSuisse
published on GitHub
13 hours ago
Weblate has an argument injection in management console
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.
Matching in nixpkgs
Web based translation tool with tight version control integration
Ignored packages (6)
Language definitions used by Weblate
Language definitions used by Weblate
Language definitions used by Weblate