Junglewise Threat Intelligence

CVE-2026-34242: Weblate arbitrary file read via symlink in ZIP download

CVE-2026-34242 · Severity: high · CVSS 7.7 · Published 2026-04-16

Technologies: weblate (PyPI). Vendors: PyPI.

Executive brief

Weblate is a web-based translation management system. A security vulnerability in its ZIP download feature allows users with low-level access to read sensitive files from the underlying server that they should not be able to see. This could lead to the exposure of configuration files, credentials, or other private system data.

Technical details

A path traversal and symlink following vulnerability exists in Weblate's ZIP download functionality. The application fails to properly validate files before inclusion in the generated ZIP archive, allowing it to follow symbolic links that point to locations outside the intended repository directory. An authenticated attacker with network access can exploit this to read arbitrary files from the host filesystem. The vulnerability is addressed in version 5.17.

Affected products

  • WeblateOrg Weblate < 5.17

Timeline

  • 2026-04-15: patched: Fix published in version 5.17
  • 2026-04-16: advisory: GitHub Advisory GHSA-hv99-mxm5-q397 published

References

Related threats