HackerOne Disclosed Reports - 2026-09-15

0 Replies, 2 Views

Logo
High
resolved

Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution


Bug reported by Shawky was disclosed at September 15, 2026, 8:36 am   |   OS Command Injection

A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-edit permission to inject Mercurial configuration and execute arbitrary commands as the Weblate service account. The vulnerability affected Weblate versions 4.11.1 through 2026.7.1 and was later assigned CVE-2026-86035.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)