CVE-2026-41654
published 2026-05-07CVE-2026-41654: Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for…
PriorityP353high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.50%
40.5th percentile
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17.1 | 5.17.1 |
| weblate | weblate | >= 0 < 5.17.1 | 5.17.1 |
| weblateorg | weblate | < 5.17.1 | 5.17.1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
weblate up to 5.17.0 full_clean information disclosure
vuldb·2026-05-07·CVSS 5.3
CVE-2026-41654 [MEDIUM] weblate up to 5.17.0 full_clean information disclosure
A vulnerability was found in weblate up to 5.17.0. It has been rated as problematic. Affected by this issue is the function full_clean. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2026-41654. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
ghsa·2026-04-30
CVE-2026-41654 [MEDIUM] CWE-20 Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
### Impact
An authenticated user with `project.add` permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose `components/.json` contains an attacker-chosen `repo` URL pointing at a **private address** (e.g. `http://127.0.0.1:9999/`) or using a **non-allow-listed scheme** (e.g. `file://`, `git://`). Weblate persists the component via `Component.objects.bulk_create([component])[0]`, which bypasses Django's `full_clean()` and therefore never runs the `validate_repo_url` validator. The URL is subsequently written verbatim into `.git/config` by `configure_repo(pull=False)`.
### Patches
* https://github.com/Weblate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/WeblateOrg/weblate/commit/e1eff1f517c1ee315d69581910baaabb724e5ef0https://github.com/WeblateOrg/weblate/commit/e4b67a76d95d5165ecb9937f7485fd79223b7f14https://github.com/WeblateOrg/weblate/pull/19061https://github.com/WeblateOrg/weblate/pull/19062https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.17.1https://github.com/WeblateOrg/weblate/security/advisories/GHSA-cwcx-382v-8m9g
2026-05-07
Published