CVE-2026-33435
HIGHWeblate: Remote code execution during backup restoration
Title source: cnaDescription
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-558g-h753-6m33
X_Refsource_Misc x_refsource_misc
https://github.com/WeblateOrg/weblate/pull/18549
Scores
CVSS v3
8.0
EPSS
0.0071
EPSS Percentile
48.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-23
CWE-434
CWE-94
Status
published
Products (4)
pypi/weblate
0 - 5.17PyPI
pypi/Weblate
0 - 5.17PyPI
weblate/weblate
< 5.17
WeblateOrg/weblate
< 5.17
Published
Apr 15, 2026
Tracked Since
Apr 16, 2026