CVE-2026-23535

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:wlc:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:21

Type Values Removed Values Added
References () https://github.com/WeblateOrg/wlc/security/advisories/GHSA-mmwx-79f6-67jg - Patch, Vendor Advisory, Mitigation () https://github.com/WeblateOrg/wlc/security/advisories/GHSA-mmwx-79f6-67jg - Mitigation, Patch, Vendor Advisory
Summary
  • (es) wlc es un cliente de línea de comandos de Weblate que utiliza la API REST de Weblate. Antes de la versión 1.17.2, la descarga de múltiples traducciones podría escribir en una ubicación arbitraria cuando era instruida por un servidor malicioso. Esta vulnerabilidad está corregida en la versión 1.17.2.

18 Feb 2026, 16:26

Type Values Removed Values Added
First Time Weblate wlc
Weblate
CPE cpe:2.3:a:weblate:wlc:*:*:*:*:*:*:*:*
References () https://github.com/WeblateOrg/wlc/commit/216e691c6e50abae97fe2e4e4f21501bf49a585f - () https://github.com/WeblateOrg/wlc/commit/216e691c6e50abae97fe2e4e4f21501bf49a585f - Patch
References () https://github.com/WeblateOrg/wlc/pull/1128 - () https://github.com/WeblateOrg/wlc/pull/1128 - Issue Tracking, Patch
References () https://github.com/WeblateOrg/wlc/releases/tag/1.17.2 - () https://github.com/WeblateOrg/wlc/releases/tag/1.17.2 - Product, Release Notes
References () https://github.com/WeblateOrg/wlc/security/advisories/GHSA-mmwx-79f6-67jg - () https://github.com/WeblateOrg/wlc/security/advisories/GHSA-mmwx-79f6-67jg - Patch, Vendor Advisory, Mitigation

16 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 19:16

Updated : 2026-06-17 10:21


NVD link : CVE-2026-23535

Mitre link : CVE-2026-23535

CVE.ORG link : CVE-2026-23535


JSON object : View

Products Affected

weblate

  • wlc
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')