CVE-2026-23535
Impact
Multi-translation download could write to an arbitrary location when instructed by a crafted server.
Patches
- https://github.com/WeblateOrg/wlc/pull/1128
Workarounds
Do not use wlc download with untrusted servers.
References
This issue was reported to us by wh1zee via HackerOne.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/WeblateOrg/wlc/security/advisories/GHSA-mmwx-79f6-67jg, https://nvd.nist.gov/vuln/detail/CVE-2026-23535, https://github.com/WeblateOrg/wlc/pull/1128, https://github.com/WeblateOrg/wlc/commit/216e691c6e50abae97fe2e4e4f21501bf49a585f, https://github.com/WeblateOrg/wlc, https://github.com/WeblateOrg/wlc/releases/tag/1.17.2
