CVE 6.6 MEDIUM

Weblate has an argument injection in management console_CVE-2026-24126

6.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Description

Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.

Basic Information

ID CVE-2026-24126
Source GitHub_M
Published Feb 18, 2026 at 23:05

Affected Product

Vendor WeblateOrg
Product weblate
Version < 5.16.0
Affected Versions WeblateOrg weblate < 5.16.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.