CVE-2026-41654
HIGH WAF: MediumWeblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/
WAF Coverage Analysis
OWASP: A03:2021 Injection
OWASP: A10:2021 SSRF
Affected Software
| Vendor | Product | Version |
|---|---|---|
| weblate | weblate | up to 5.17.1 |
References
- github.com (Patch)
- github.com (Patch)
- github.com (Issue Tracking, Patch)
- github.com (Issue Tracking, Patch)
- github.com (Release Notes)
- github.com (Patch, Vendor Advisory)