CVE-2026-23535: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-23535 is a path traversal vulnerability in wlc, the Weblate command-line client that interacts with Weblate's REST API. Prior to version 1.17.2, the multi-translation download feature failed to sanitize server-provided API slugs (project and component names), allowing a crafted server to instruct the client to write downloaded files to arbitrary filesystem locations. It affects all wlc versions before 1.17.2 and was disclosed on January 16, 2026. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). In wlc/main.py, the download_component function constructed output file paths by directly interpolating component.project.slug and component.slug values returned by the server into a Path object (e.g., directory / f"{component.project.slug}-{component.slug}.zip"), without validating or sanitizing those values. A malicious Weblate server could return slugs containing path traversal sequences such as ../ or ..\, causing the client to write the downloaded ZIP file outside the intended output directory. Exploitation requires the victim to have valid (low-privilege) credentials and to actively run the wlc download command against a malicious server, and the attack crosses a scope boundary since the client's filesystem is impacted beyond the application's own directory (GitHub Advisory, Fix PR #1128, Fix Commit).

Impact

A successful exploit allows an attacker controlling a malicious Weblate server to write arbitrary file content (a ZIP archive) to any location on the victim's filesystem where the wlc process has write permissions. This can lead to overwriting sensitive configuration files, planting malicious scripts in startup or cron directories, or achieving arbitrary code execution — resulting in high confidentiality, integrity, and availability impact. The changed scope means the attack can affect system components beyond the wlc application itself, enabling potential lateral movement or persistent access on the victim's machine (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.032%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to control or compromise a Weblate server instance that the victim's wlc client connects to, and the victim must actively execute the wlc download command (GitHub Advisory, Feedly).

Exploitation steps

  1. Set up a malicious Weblate server: The attacker deploys or compromises a Weblate server instance and configures it to return crafted API responses. The server is set up to accept authentication from the target user.
  2. Craft malicious API slugs: The attacker configures a project or component on the malicious server with slugs containing path traversal sequences, e.g., a project slug of ../../etc and a component slug of cron.d/backdoor, so the resulting filename becomes ../../etc/cron.d/backdoor.zip.
  3. Lure the victim: The attacker convinces the victim (e.g., a developer or CI pipeline) to configure wlc to point to the malicious server (via WLC_URL, --url, or a config file) and to run wlc download.
  4. Trigger the download: When the victim executes wlc download, the client authenticates to the malicious server, retrieves the translation component list with the crafted slugs, and constructs the output file path without sanitization.
  5. Arbitrary file write: The client writes the attacker-controlled ZIP content to the traversed path (e.g., /etc/cron.d/backdoor.zip), potentially overwriting sensitive files or planting malicious content for code execution (GitHub Advisory, Fix Commit).

Indicators of compromise

  • File System: Unexpected .zip files written outside the intended output directory, particularly in sensitive locations such as /etc/, home directories, cron directories, or shell profile directories; file timestamps on system files matching the time of a wlc download invocation.
  • Logs: Shell history or CI/CD logs showing wlc download commands executed against an unfamiliar or external Weblate server URL; audit logs (e.g., auditd) recording file write events by the wlc process to unexpected paths.
  • Process: The wlc process (Python) writing files to paths outside the configured output directory; unexpected child processes spawned shortly after a wlc download invocation if a planted script was executed.
  • Network: Outbound connections from developer workstations or CI systems to unfamiliar Weblate API endpoints (non-standard URLs in WLC_URL or config files).

Mitigation and workarounds

Upgrade wlc to version 1.17.2 or later, which introduces a sanitize_slug() utility function that replaces all non-alphanumeric (except underscore) characters in server-provided slugs with dashes before constructing file paths, preventing traversal (Fix PR #1128, Fix Commit). Until patching is complete, avoid running wlc download against untrusted or unverified Weblate servers. Additionally, restrict wlc process filesystem permissions using least-privilege principles to limit the impact of any arbitrary file write (GitHub Advisory).

Community reactions

The vulnerability was reported to the Weblate project via HackerOne by researcher wh1zee (also credited as Zee99y) and was promptly patched by maintainer nijel on January 15, 2026, with the advisory published the following day (GitHub Advisory). The MusicBrainz Picard project noted the vulnerability and updated their wlc dependency shortly after disclosure (Fix PR #1128). Coverage was picked up by security aggregators including Tenable Nessus (plugin 291278), Red Hat, and community security feeds, though no major media coverage or significant social media discussion has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

wlc

Affected

sid

wlc: 1.17.2-1

Fixed

trixie

wlc

Affected

Ubuntu

Unknown

bionic (esm-apps)

wlc

Unknown

devel

wlc

Unknown

focal (esm-apps)

wlc

Unknown

jammy

wlc

Unknown

jammy (esm-apps)

wlc

Unknown

noble

wlc

Unknown

noble (esm-apps)

wlc

Unknown

resolute

wlc

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management