CVE-2026-23535High· 8.0▾ TwilightWeblate wlc path traversal vulnerability: Unsanitized API slugs in download command
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
Multi-translation download could write to an arbitrary location when instructed by a crafted server.
Do not use wlc download with untrusted servers.
This issue was reported to us by wh1zee via HackerOne.
wlc < 1.17.2Upgrade to a patched release:
wlc 1.17.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42150Medium· 5.1wlc: print_html outputs API data without HTML escaping
CVE-2026-22251Medium· 5.3Weblate wlc has insecure API key configuration
CVE-2026-22250Low· 2.5Weblate command-line client susceptible to SSL verification skip