Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61792— Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)

Quick assessment

Affected
WeblateOrg weblate
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.7 之前的版本中,项目管理员可以通过 App 商店元数据下载功能读取其仓库之外的文件,因为该功能在解析受攻击者影响的路径时,未能充分将路径限制在仓库内。这是 CVE-2026-34242 的不完整修复,其原始补丁未能完全阻止路径遍历,导致任意文件读取漏洞依然存在。因此,拥有项目管理员权限的用户可以泄露 Weblate 主机上位于项目仓库之外的文件内容。该问题已在 2026.7 版本中修复。

CVSS 7.7 · High

Possible ATT&CK Techniques 2 AI

T1212.001 T1005.001
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61792

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)
Source: CVE Program / CVE List V5
Vulnerability Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the repository. This is an incomplete fix for CVE-2026-34242, whose original patch failed to fully prevent the path traversal, allowing the arbitrary file read to persist. A user with project-administrator privileges can therefore disclose the contents of files on the Weblate host that lie outside the project's repository. This issue is fixed in version 2026.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WeblateOrg weblate < 2026.7 -

II. Public POCs for CVE-2026-61792

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8957 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-61792

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61792 (2)

Vendor Advisories for CVE-2026-61792 (1)

Same Patch Batch · WeblateOrg · 2026-08-26 · 9 CVEs total

CVE-2026-55228 8.1 HIGH Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize
CVE-2026-62326 6.5 MEDIUM Weblate Has Uncontrolled Resource Consumption via
CVE-2026-77507 5.3 MEDIUM Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
CVE-2026-61790 4.4 MEDIUM Weblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-62249 4.3 MEDIUM Weblate: Restricted-component change history leaked to non-member project users through th
CVE-2026-55227 4.3 MEDIUM Observable object existence disclosure in private Weblate projects via globally scoped obj
CVE-2026-77508 3.5 LOW Weblate: Unverified REST API email changes
CVE-2026-77573 3.5 LOW Weblate: DNS rebinding in VCS operations allows server-side request forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-61792

No comments yet


Leave a comment