Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-558g-h753-6m33

Опубликовано: 16 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Weblate: Remote code execution during backup restoration

Impact

The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.

Patches

Workarounds

The project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability.

References

This issue was reported by ggamno via HackerOne.

Пакеты

Наименование

Weblate

pip
Затронутые версииВерсия исправления

< 5.17

5.17

EPSS

Процентиль: 50%
0.00708
Низкий

8 High

CVSS3

Дефекты

CWE-23
CWE-434
CWE-94

Связанные уязвимости

CVSS3: 8
nvd
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.

CVSS3: 8
debian
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, t ...

EPSS

Процентиль: 50%
0.00708
Низкий

8 High

CVSS3

Дефекты

CWE-23
CWE-434
CWE-94