Path Traversal Vulnerability in Weblate Localization Tool
CVE-2026-40256
5MEDIUM
What is CVE-2026-40256?
Weblate, a web-based localization tool, has a vulnerability in its repository-boundary validation mechanism. In versions prior to 5.17, this mechanism relies on string prefix checks, which are not adequately path-segment aware. This flaw allows attackers to potentially bypass the security by using external paths that share the same string prefix as the legitimate repository path (e.g., prefix 'repo' and 'repo_outside'). This vulnerability has been addressed in version 5.17, highlighting the importance of updating to the latest release.
Affected Version(s)
weblate < 5.17
