CVE-2026-34242 is a path traversal vulnerability in Weblate versions prior to 5.17 that affects the ZIP download feature. The vulnerability occurs because downloaded files are not properly verified, allowing attackers to potentially follow symlinks outside the intended repository directory and access sensitive files. This issue has been patched in Weblate version 5.17 and later. The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring only low complexity and low privileges to exploit. An authenticated user can trigger the vulnerability without user interaction, and successful exploitation could result in high confidentiality impact with cross-site scope, though integrity and availability are not affected. The EPSS score of 0.00015 indicates relatively low prevalence compared to other CVEs. There is currently no evidence of active exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Community attention appears minimal with the vulnerability remaining on the inactive Hot List, suggesting limited awareness or immediate threat. Organizations using Weblate should prioritize upgrading to version 5.17 to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.17CPE matchmatch criteria | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.