<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 06:29:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-268864</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-268864</link>
      <description>EUVD-2026-268864</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-268864</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24126</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24126</link>
      <description>&lt;p&gt;Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24126</guid>
    </item>
    <item>
      <title>GHSA-33fm-6gp7-4p47 — Weblate has an argument injection in management console</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-33fm-6gp7-4p47</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Weblate&lt;/p&gt;
&lt;p&gt;### Impact
The SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`.&lt;/p&gt;
&lt;p&gt;### Patches
* https://github.com/WeblateOrg/weblate/pull/17722&lt;/p&gt;
&lt;p&gt;### Workarounds
Properly limit access to the management console.&lt;/p&gt;
&lt;p&gt;### References
This issue was reported to us by [alexb_616](https://hackerone.com/alexb_616) via HackerOne.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Weblate&lt;/p&gt;
&lt;p&gt;### Impact
The SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`.&lt;/p&gt;
&lt;p&gt;### Patches
* https://github.com/WeblateOrg/weblate/pull/17722&lt;/p&gt;
&lt;p&gt;### Workarounds
Properly limit access to the management console.&lt;/p&gt;
&lt;p&gt;### References
This issue was reported to us by [alexb_616](https://hackerone.com/alexb_616) via HackerOne.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-33fm-6gp7-4p47</guid>
    </item>
    <item>
      <title>PYSEC-2026-2309</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2309</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: weblate&lt;/p&gt;
&lt;p&gt;Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: weblate&lt;/p&gt;
&lt;p&gt;Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2309</guid>
    </item>
  </channel>
</rss>
