CVE-2026-23535 describes a path traversal vulnerability in the wlc Weblate command-line client, affecting versions prior to 1.17.2. A crafted Weblate server could instruct wlc to write downloaded multi-translations to an arbitrary file system location. This vulnerability carries a high CVSS score of 8.0, indicating a high impact on confidentiality, integrity, and availability, with a network attack vector and high complexity due to user interaction. There is currently no evidence of active exploitation, and no public exploit code is available, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.2CPE matchmatch criteria | cpe:2.3:a:weblate:wlc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.