Dark C0d3rs
HackerOne Disclosed Reports - 2026-09-15 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-09-15 (/Thread-HackerOne-Disclosed-Reports-2026-09-15)



HackerOne disclosed reports - 2026-09-15 - hashXploiter - 09-16-2026

Logo
High
resolved

Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution


Bug reported by Shawky was disclosed at September 15, 2026, 8:36 am   |   OS Command Injection

A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-edit permission to inject Mercurial configuration and execute arbitrary commands as the Weblate service account. The vulnerability affected Weblate versions 4.11.1 through 2026.7.1 and was later assigned CVE-2026-86035.