CVE-2026-86035High· 8.5▾ TwilightWeblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - co…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2025-61587Medium· 6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API