Junglewise Threat Intelligence

CVE-2026-44264: Weblate XSS in Markdown renderer via image attributes

CVE-2026-44264 · Severity: medium · CVSS 4.3 · Published 2026-05-07

Technologies: WeblateOrg Weblate. Vendors: PyPI.

Executive brief

Weblate is a web-based platform used by organizations to manage software translation and localization. A security flaw in how the system handles user-provided comments and content could allow an attacker to inject malicious code into the interface. While the platform's security policies provide some protection, an exploit could potentially allow unauthorized modification of page content or user interactions.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Weblate's Markdown rendering engine due to improper neutralization of HTML attributes. Specifically, the renderer failed to escape image source (src) URLs before interpolating them into generated HTML tags. An authenticated attacker with permissions to post comments or provide content could exploit this to perform attribute injection. While Weblate's Content Security Policy (CSP) provides a layer of mitigation, the flaw allows for unauthorized integrity changes to the web page. The issue is resolved in version 5.17.1 by ensuring all image targets are explicitly escaped before being processed by the mistletoe library.

Affected products

  • WeblateOrg Weblate < 5.17.1

Timeline

  • 2026-04-27: patched: Fix committed to repository
  • 2026-04-30: advisory: GitHub Security Advisory published
  • 2026-05-07: disclosed: CVE published to NVD

References

Related threats