CVE-2026-33435

HIGH

Weblate: Remote code execution during backup restoration

Title source: cna
STIX 2.1

Description

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.

Scores

CVSS v3 8.0
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-23 CWE-434 CWE-94
Status published
Products (3)
pypi/weblate 0 - 5.17PyPI
weblate/weblate < 5.17
WeblateOrg/weblate < 5.17
Published Apr 15, 2026
Tracked Since Apr 16, 2026