Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
Description
Published to the GitHub Advisory Database
Jan 16, 2026
Reviewed
Jan 16, 2026
Published by the National Vulnerability Database
Jan 16, 2026
Last updated
Jan 16, 2026
Impact
Multi-translation download could write to an arbitrary location when instructed by a crafted server.
Patches
Workarounds
Do not use
wlc downloadwith untrusted servers.References
This issue was reported to us by wh1zee via HackerOne.
References