Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv99-mxm5-q397

Опубликовано: 16 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Weblate: Arbitrary File Read via Symlink

Impact

The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.

Patches

References

Thanks to @DavidCarliez for reporting this vulnerability via GitHub.

Пакеты

Наименование

weblate

pip
Затронутые версииВерсия исправления

< 5.17

5.17

EPSS

Процентиль: 38%
0.00465
Низкий

7.7 High

CVSS3

Дефекты

CWE-200
CWE-22
CWE-59

Связанные уязвимости

CVSS3: 7.7
nvd
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.

CVSS3: 7.7
debian
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, t ...

EPSS

Процентиль: 38%
0.00465
Низкий

7.7 High

CVSS3

Дефекты

CWE-200
CWE-22
CWE-59