Impact
The vulnerability is a path‑traversal flaw in Weblate’s App store metadata download that allows a user with project‑administrator rights to read files outside the project’s repository. The flaw stems from insufficient path confinement and is an incomplete remediation of a prior flaw, enabling the disclosure of any files located on the Weblate host. This results in confidentiality compromise rather than code execution, and corresponds to the weaknesses listed under CWE‑22, CWE‑59 and CWE‑693.
Affected Systems
All Weblate installations running a version earlier than 2026.7 are affected. The issue is fixed in version 2026.7 and later releases of the Weblate platform by WeblateOrg.
Risk and Exploitability
The CVSS score of 7.7 marks it as a high‑severity vulnerability. The attack vector requires a legitimate project‑administrator account and can be performed via the normal web interface, making it accessible to any user who has that level of privilege. Since the vulnerability exposes arbitrary host files, the potential impact on confidentiality is substantial. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting exploitation is not currently widespread, but the risk remains significant for enabled administrators.
OpenCVE Enrichment