CVE-2026-34242: Weblate: Arbitrary File Read via Symlink
Impact
The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.
Patches
https://github.com/WeblateOrg/weblate/pull/18683
References
Thanks to @DavidCarliez for reporting this vulnerability via GitHub.
Other sources
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34242?
The severity of CVE-2026-34242 is considered high due to the potential for arbitrary file read through symlinks.
How do I fix CVE-2026-34242?
To fix CVE-2026-34242, upgrade to Weblate version 5.17 or later.
What versions of Weblate are affected by CVE-2026-34242?
All versions of Weblate prior to 5.17 are affected by CVE-2026-34242.
What type of vulnerability is CVE-2026-34242?
CVE-2026-34242 is an arbitrary file read vulnerability caused by improper symlink verification.
Is there a patch available for CVE-2026-34242?
Yes, a patch is available in the updated version 5.17 of Weblate.