CVE-2024-39303

MEDIUM

Weblate <5.6.2 - Code Injection

Title source: llm
STIX 2.1

Description

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaround, do not allow untrusted users to create projects.

Scores

CVSS v3 4.4
EPSS 0.0044
EPSS Percentile 63.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-73
Status published
Products (2)
pypi/Weblate 4.14 - 5.6.2PyPI
weblate/weblate 4.14 - 5.6.2
Published Jul 01, 2024
Tracked Since Feb 18, 2026