CVE-2026-41654: Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Published Apr 30, 2026
·
Updated

Impact An authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulkcreate([component])[0], which bypasses Django's fullclean() and therefore never runs the validaterepourl validator. The URL is subsequently written verbatim into .git/config by configurerepo(pull=False).

Patches https://github.com/WeblateOrg/weblate/pull/19061 https://github.com/WeblateOrg/weblate/pull/19062

Workarounds Limiting who can create projects limits the scope.

Resources Weblate thanks @fg0x0 for reporting this vulnerability via GitHub.

Other sources

Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulkcreate([component])[0], which bypasses Django's fullclean() and therefore never runs the validaterepourl validator. The URL is subsequently written verbatim into .git/config by configurerepo(pull=False). This issue has been patched in version 5.17.1.

MITRE

Affected Software

2 affected componentsFixes available
pip/weblate<5.17.1
5.17.1
Weblate weblate<5.17.1

Event History

Apr 30, 2026
Advisory Published
via GitHub·05:28 PM
Data Sourced
via GitHub·05:28 PM
DescriptionWeaknessAffected Software
May 7, 2026
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41654?

CVE-2026-41654 is classified as a high-severity vulnerability due to its potential exploitation by authenticated users.

2

How do I fix CVE-2026-41654?

To fix CVE-2026-41654, upgrade Weblate to version 5.17.1 or later.

3

Who is affected by CVE-2026-41654?

CVE-2026-41654 affects authenticated users with `project.add` permission on hosted Weblate SaaS.

4

What types of attacks can exploit CVE-2026-41654?

CVE-2026-41654 can be exploited by importing a crafted project backup ZIP that contains an attacker-chosen private repo URL.

5

What permissions are required to exploit CVE-2026-41654?

Exploitation of CVE-2026-41654 requires a user to have `project.add` permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203