Weblate: Remote code execution during backup restoration
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 16, 2026
Reviewed
Apr 16, 2026
Last updated
Jun 8, 2026
Impact
The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.
Patches
Workarounds
The project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability.
References
This issue was reported by ggamno via HackerOne.
References