Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0027

NIXPKGS-2026-0027
published on 17 Jan 2026
updated 5 days, 4 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • wlcs
    • wlclock
    • imewlconverter
  • @LeSuisse accepted as draft
  • @LeSuisse published on GitHub
wlc Path traversal: Unsanitized API slugs in download command

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

Affected products

wlc
  • ==< 1.17.2

Matching in nixpkgs

Package maintainers: 4