CVE-2026-86035
Wstrzyknięcie argumentów w Weblate pozwala na wykonanie dowolnych poleceń przez uwierzytelnionego użytkownika.
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-09-29 15:17:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 13:18:01 UTC |
- https://github.com/WeblateOrg/weblate/commit/f60a9759a6d851bd10ccdefe9b1b7f0cdb9e9bbd ([email protected])
- https://github.com/WeblateOrg/weblate/pull/20768 ([email protected])
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.8 ([email protected])
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-327h-qqgm-qv55 ([email protected])