Launch Week Day 1: Announcing Security Design Review
HIGH 7.7 PyPI

Weblate: Arbitrary File Read via Symlink

GHSA-hv99-mxm5-q397 · CVE-2026-34242

Published · Modified

Description

Impact

The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.

Patches

References

Thanks to @DavidCarliez for reporting this vulnerability via GitHub.

Ready to move

Start Securing

Free, no credit card | First findings in minutes