<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:08:59.817827+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33435</id>
    <title>CVE-2026-33435 — Weblate: Remote code execution during backup restoration</title>
    <updated>2026-10-04T21:08:59.819473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> WeblateOrg weblate</p>
<p>Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by restricting access to the project backup, as it is only accessible to users who can create projects.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-558g-h753-6m33</id>
    <title>GHSA-558g-h753-6m33 — Weblate: Remote code execution during backup restoration</title>
    <updated>2026-10-04T21:08:59.819524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Weblate</p>
<p>### Impact
The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.</p>
<p>### Patches
* https://github.com/WeblateOrg/weblate/pull/18549</p>
<p>### Workarounds
The project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability.</p>
<p>### References
This issue was reported by [ggamno](https://hackerone.com/ggamno) via HackerOne.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-558g-h753-6m33"/>
  </entry>
</feed>
