← Terug naar overzicht

CVE-2026-61792 is a path traversal vulnerability in Weblate, a web-based continuous localization platform for managing software translations. In versions prior to 2026.7, a project administrator can read arbitrary files outside the repository via the App store metadata download feature, which fails to adequately confine resolved paths to the repository. This vulnerability is an incomplete fix for a prior related issue, CVE-2026-34242, whose original patch did not fully prevent the path traversal. The flaw allows users with project-administrator privileges to disclose the contents of sensitive files on the Weblate host system. The issue has been patched in Weblate version 2026.7. Two commits have been published addressing the vulnerability along with a GitHub security advisory. Organizations using affected versions should upgrade immediately to mitigate the risk of unauthorized file disclosure.

Affected products

  • Weblate

Related CVE's

  • CVE-2026-34242
  • CVE-2026-61792

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Web Technologies