CVE-2026-23535
EUVD-2026-286416.01.2026, 19:16
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| weblate | wlc | 𝑥 < 1.17.2 |
𝑥
= Vulnerable software versions
Debian Releases