CVE-2026-23535: Weblate Wlc

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

Affected products

  • Weblate Wlc: before 1.17.2 (fixed in 1.17.2)

Published 2026-01-16. Last modified 2026-06-17.