Path Traversal Vulnerability in Weblate Localization Tool
CVE-2026-40256

5MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-40256?

Weblate, a web-based localization tool, has a vulnerability in its repository-boundary validation mechanism. In versions prior to 5.17, this mechanism relies on string prefix checks, which are not adequately path-segment aware. This flaw allows attackers to potentially bypass the security by using external paths that share the same string prefix as the legitimate repository path (e.g., prefix 'repo' and 'repo_outside'). This vulnerability has been addressed in version 5.17, highlighting the importance of updating to the latest release.

Affected Version(s)

weblate < 5.17

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.