Weblate: Arbitrary File Read via Symlink
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 16, 2026
Reviewed
Apr 16, 2026
Last updated
Apr 16, 2026
Impact
The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.
Patches
References
Thanks to @DavidCarliez for reporting this vulnerability via GitHub.
References