CVE-2026-34242 - Weblate: Arbitrary File Read via Symlink
CVE ID :CVE-2026-34242
Published : April 15, 2026, 7:16 p.m. | 24 minutes ago
Description :Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 15, 2026, 7:16 p.m. | 24 minutes ago
Description :Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...