HIGH 7.7 PyPI
Weblate: Arbitrary File Read via Symlink
GHSA-hv99-mxm5-q397 · CVE-2026-34242
Published · Modified
Description
Impact
The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.
Patches
References
Thanks to @DavidCarliez for reporting this vulnerability via GitHub.
Ready to move
Start Securing
Free, no credit card | First findings in minutes