CVE-2026-33220

MEDIUM

Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository

Title source: cna
STIX 2.1

Description

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/WeblateOrg/weblate/pull/18516

Scores

CVSS v3 6.8
EPSS 0.0032
EPSS Percentile 23.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-22
Status published
Products (4)
pypi/weblate 0 - 5.17PyPI
pypi/Weblate 0 - 5.17PyPI
weblate/weblate < 5.17
WeblateOrg/weblate < 5.17
Published Apr 15, 2026
Tracked Since Apr 16, 2026