CVE-2026-23535 - wlc Path traversal: Unsanitized API slugs in download command

CVE-2026-23535 - wlc Path traversal: Unsanitized API slugs in download command

CVE ID : CVE-2026-23535 Published : Jan. 16, 2026, 7:16 p.m. | 1 hour, 1 minute ago Description : wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Jan. 16, 2026