CVE-2026-23535

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-16 19:16

Updated : 2026-01-26 15:05


NVD link : CVE-2026-23535

Mitre link : CVE-2026-23535

CVE.ORG link : CVE-2026-23535


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')