
CVE at Weblate: CVE-2026-40256 , i actually discovered this bug last month but i've been too unmotivated to share or even do anything lately bug was a path traversal caused by unsafe startswith() path validation (repo vs repo_outside) u can reach it at : https://www.cve.org/CVERecord?id=CVE-2026-40256 https://t.co/Pqd0PohFT8
Post summary
The post announces a recently discovered path traversal bug in Weblate (CVE‑2026‑40256), providing specific technical details but no proof of exploitation or patch information.


