Weblate has an argument injection in management console
Moderate severity
GitHub Reviewed
Published
Feb 16, 2026
in
WeblateOrg/weblate
•
Updated Feb 19, 2026
Description
Published to the GitHub Advisory Database
Feb 17, 2026
Reviewed
Feb 17, 2026
Published by the National Vulnerability Database
Feb 19, 2026
Last updated
Feb 19, 2026
Impact
The SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to
ssh-add.Patches
Workarounds
Properly limit access to the management console.
References
This issue was reported to us by alexb_616 via HackerOne.
References