Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.
References
| Link | Resource |
|---|---|
| https://github.com/WeblateOrg/weblate/commit/78773cc141ce0a97900c11341e6cf856451395fd | Patch |
| https://github.com/WeblateOrg/weblate/pull/17722 | Issue Tracking |
| https://github.com/WeblateOrg/weblate/security/advisories/GHSA-33fm-6gp7-4p47 | Patch Vendor Advisory |
Configurations
History
19 Feb 2026, 18:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/WeblateOrg/weblate/commit/78773cc141ce0a97900c11341e6cf856451395fd - Patch | |
| References | () https://github.com/WeblateOrg/weblate/pull/17722 - Issue Tracking | |
| References | () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-33fm-6gp7-4p47 - Patch, Vendor Advisory | |
| First Time |
Weblate
Weblate weblate |
|
| CPE | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | |
| Summary |
|
19 Feb 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 00:16
Updated : 2026-02-19 18:34
NVD link : CVE-2026-24126
Mitre link : CVE-2026-24126
CVE.ORG link : CVE-2026-24126
JSON object : View
Products Affected
weblate
- weblate
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
