PT-2026-33125 · Weblate · Weblate

CVE-2026-40256

·

Published

2026-04-15

·

Updated

2026-05-15

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description Repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This process is not path-segment aware and can be bypassed when an external path shares the same string prefix as the repository path, such as when one path is named repo and another is repo outside.
Recommendations Update to version 5.17.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40256
GHSA-FFGH-3JRF-8WVH
PYSEC-2026-2315

Affected Products

Weblate