Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-09-15
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
High
resolved

Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution


Bug reported by Shawky was disclosed at September 15, 2026, 8:36 am   |   OS Command Injection

A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-edit permission to inject Mercurial configuration and execute arbitrary commands as the Weblate service account. The vulnerability affected Weblate versions 4.11.1 through 2026.7.1 and was later assigned CVE-2026-86035.