CVE-2026-86035: Weblate: Mercurial argument injection via repository filenames allows authenticated command execution
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Weblateto a version that resolves this vulnerability.Fixed in 2026.8
Event History
Frequently Asked Questions
Which deployments are exposed to exploitation?
Affected deployments are Weblate versions 4.11.1 through 2026.7.1 that use a Mercurial-backed RESX component with the Update RESX files add-on. The attacker must have an authenticated account with project-scoped component.edit permission.
What access and conditions does an attacker need?
An attacker needs component.edit permission in the relevant project and must be able to introduce a repository filename beginning with a hyphen. Exploitation is triggered when a later repository update causes Mercurial to interpret that filename as an option.
What is the impact of successful exploitation?
A successful exploit can execute arbitrary commands with the privileges of the Weblate service account. The vulnerability can therefore affect confidentiality, integrity, and availability beyond the compromised project scope.
What version resolves the issue?
The issue is patched in Weblate version 2026.8. Systems running versions from 4.11.1 through 2026.7.1 are affected according to the provided data.