
CVE-2026-34242 Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside … https://www.cve.org/CVERecord?id=CVE-2026-34242
Post summary
The CVE details how Weblate’s ZIP download function can follow symlinks outside the intended directory in versions before 5.17, exposing a potential path traversal flaw.
