Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects. | |
| Title | Weblate: Remote code execution during backup restoration | |
| Weaknesses | CWE-23 CWE-434 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-15T18:40:27.204Z
Reserved: 2026-03-19T18:45:22.436Z
Link: CVE-2026-33435
Updated: 2026-04-15T18:40:21.788Z
Status : Received
Published: 2026-04-15T19:16:35.277
Modified: 2026-04-15T19:16:35.277
Link: CVE-2026-33435
No data.
OpenCVE Enrichment
No data.