Executive brief
Weblate is a web-based platform used by organizations to manage software translation and localization. A security vulnerability in the project import feature allows authorized users to bypass safety checks and force the server to connect to internal or restricted network addresses. This could lead to the exposure of sensitive internal data or unauthorized access to private infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Weblate's project backup restoration process. When importing a project ZIP, the application uses Django's 'bulk_create' method to persist component metadata from JSON files, which bypasses the 'full_clean()' method and the associated 'validate_repo_url' validator. An attacker with 'project.add' permissions can provide a crafted ZIP containing malicious repository URLs (e.g., pointing to 127.0.0.1 or using file:// schemes). These URLs are written verbatim to the .git/config file, allowing the attacker to probe internal services or access local files when the repository is subsequently initialized or updated. This issue is fixed in version 5.17.1 by explicitly revalidating VCS URLs during the backup validation phase.
Affected products
- WeblateOrg Weblate < 5.17.1
Timeline
- 2026-04-17: patched: Fixes committed to main branch and tagged for 5.17.1 release.
- 2026-05-07: disclosed: CVE-2026-41654 published.
References
- https://github.com/WeblateOrg/weblate/commit/e1eff1f517c1ee315d69581910baaabb724e5ef0
- https://github.com/WeblateOrg/weblate/commit/e4b67a76d95d5165ecb9937f7485fd79223b7f14
- https://github.com/WeblateOrg/weblate/pull/19061
- https://github.com/WeblateOrg/weblate/pull/19062
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.17.1
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-cwcx-382v-8m9g