CVE-2026-33435
published 2026-04-15CVE-2026-33435: Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to…
PriorityP345high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
weblate up to 5.16 Configuration path traversal (GHSA-558g-h753-6m33)
vuldb·2026-04-16·CVSS 8.0
CVE-2026-33435 [HIGH] weblate up to 5.16 Configuration path traversal (GHSA-558g-h753-6m33)
A vulnerability was found in weblate up to 5.16. It has been rated as problematic. This affects an unknown function of the component Configuration Handler. This manipulation causes relative path traversal.
This vulnerability is registered as CVE-2026-33435. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
Weblate: Remote code execution during backup restoration
ghsa·2026-04-16
CVE-2026-33435 [HIGH] CWE-23 Weblate: Remote code execution during backup restoration
Weblate: Remote code execution during backup restoration
### Impact
The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18549
### Workarounds
The project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability.
### References
This issue was reported by [ggamno](https://hackerone.com/ggamno) via HackerOne.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published