CVE-2026-40256
published 2026-04-15CVE-2026-40256: Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths…
PriorityP430medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.32%
25.6th percentile
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). This issue has been fixed in version 5.17.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
ghsa·2026-04-16
CVE-2026-40256 [MEDIUM] CWE-22 Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
### Impact
Weblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside).
### Patches
* https://github.com/WeblateOrg/weblate/pull/18847
### References
Thanks to [m9nx4u](https://hackerone.com/m9nx4u) for reporting this issue via HackerOne.
VulDB
weblate up to 5.16 repo_outside path traversal (GHSA-ffgh-3jrf-8wvh)
vuldb·2026-04-16·CVSS 5.0
CVE-2026-40256 [MEDIUM] weblate up to 5.16 repo_outside path traversal (GHSA-ffgh-3jrf-8wvh)
A vulnerability was found in weblate up to 5.16 and classified as critical. This affects the function repo_outside. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-40256. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published