Vulnerability in Weblate Localization Tool Allows Unchecked Repo URLs from Project Backups
CVE-2026-41654

5.3MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41654?

Weblate, a widely-used web-based localization tool, allows authenticated users with project.add permissions to import project backup ZIP files containing malicious URLs. Specifically, an attacker can embed a crafted repo URL in the components/.json file, which can point to non-allowed schemes or private addresses. This bypasses critical validation checks in Django, leading to sensitive configurations being altered without proper verification. The issue affects versions prior to 5.17.1 and has been remediated in the latest release.

Affected Version(s)

weblate < 5.17.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.