CVE-2026-24126
MEDIUMWeblate <5.16.0 - Command Injection
Title source: llmDescription
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.
Exploits (1)
Scores
CVSS v3
6.6
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Details
CWE
CWE-88
Status
published
Products (2)
pypi/Weblate
0 - 5.16.0PyPI
weblate/weblate
< 5.16
Published
Feb 19, 2026
Tracked Since
Feb 19, 2026