VULNERABILITY OVERVIEW CVE-2026-40256 is a path traversal vulnerability affecting Weblate, a web-based localization platform, in all versions prior to 5.17. The flaw stems from improper repository-boundary validation that relies on string prefix checks rather than proper path-segment validation. An attacker can bypass these checks when an external path shares a common string prefix with the repository root path (such as "repo" and "repo_outside"), potentially allowing unauthorized access to files outside the intended repository boundaries. SEVERITY ASSESSMENT The vulnerability carries a CVSS 3.1 score of 5.0 (MEDIUM severity) with a network-based attack vector requiring low complexity and authenticated access. The impact is limited to low-level information disclosure with no integrity or availability impact. The EPSS score of 0.00017 indicates minimal current exploitation probability relative to other CVEs, though the FAUCET risk score of 31.0/100 suggests moderate organizational concern. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability has not been included in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploit code is documented. Community attention remains minimal, with the Hot List status marked as inactive. Organizations should prioritize upgrading to version 5.17 or later as a precautionary measure, though immediate emergency response is not warranted given the low exploitation probability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.17CPE matchmatch criteria | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.