CVE-2026-33435
HIGHWeblate: Remote code execution during backup restoration
Title source: cnaDescription
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.
Scores
CVSS v3
8.0
EPSS
0.0010
EPSS Percentile
28.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-23
CWE-434
CWE-94
Status
published
Products (3)
pypi/weblate
0 - 5.17PyPI
weblate/weblate
< 5.17
WeblateOrg/weblate
< 5.17
Published
Apr 15, 2026
Tracked Since
Apr 16, 2026