HIGH 8.0 PyPI

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

GHSA-mmwx-79f6-67jg · CVE-2026-23535 · PYSEC-2026-2053

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Multi-translation download could write to an arbitrary location when instructed by a crafted server.

Patches

Workarounds

Do not use wlc download with untrusted servers.

References

This issue was reported to us by wh1zee via HackerOne.

Ready to move

Start Securing

Free, no credit card | First findings in minutes