HIGH 8.0 PyPI
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
GHSA-mmwx-79f6-67jg · CVE-2026-23535 · PYSEC-2026-2053
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Multi-translation download could write to an arbitrary location when instructed by a crafted server.
Patches
Workarounds
Do not use wlc download with untrusted servers.
References
This issue was reported to us by wh1zee via HackerOne.
References
- WEB https://github.com/WeblateOrg/wlc/security/advisories/GHSA-mmwx-79f6-67jg
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-23535
- WEB https://github.com/WeblateOrg/wlc/pull/1128
- WEB https://github.com/WeblateOrg/wlc/commit/216e691c6e50abae97fe2e4e4f21501bf49a585f
- PACKAGE https://github.com/WeblateOrg/wlc
- WEB https://github.com/WeblateOrg/wlc/releases/tag/1.17.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes