Weblate Localization Tool Vulnerability Exposes Project Backup Risks
CVE-2026-33435

8.1HIGH

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-33435?

Weblate, a web-based localization tool, has a vulnerability in its project backup process that failed to filter sensitive Git and Mercurial configuration files. As a result, under specific circumstances, this flaw could allow unauthorized remote code execution. The issue has been addressed in version 5.17. Users who cannot immediately update are advised to restrict access to project backups, which are only accessible to users with project creation capabilities. Protect your projects by ensuring you are on the latest version.

Affected Version(s)

weblate < 5.17

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.