CVE-2026-23535: wlc Path traversal: Unsanitized API slugs in download command
Impact Multi-translation download could write to an arbitrary location when instructed by a crafted server.
Patches https://github.com/WeblateOrg/wlc/pull/1128
Workarounds Do not use wlc download with untrusted servers.
References This issue was reported to us by wh1zee via HackerOne.
Other sources
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23535?
CVE-2026-23535 has a critical severity as it allows for path traversal vulnerabilities leading to potential arbitrary file writes.
How do I fix CVE-2026-23535?
To fix CVE-2026-23535, update the 'wlc' package to version 1.17.2 or later.
Can CVE-2026-23535 be exploited by untrusted servers?
Yes, CVE-2026-23535 can be exploited through crafted servers when using the 'wlc download' command.
What are the workarounds for CVE-2026-23535?
As a workaround for CVE-2026-23535, avoid using 'wlc download' with untrusted servers.
Which versions of 'wlc' are affected by CVE-2026-23535?
CVE-2026-23535 affects all versions of 'wlc' up to and including 1.17.2.