Sceawere

Vulnerability Detail

CVE-2026-86035UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Weblate Mercurial Argument Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
10h ago
Vendor
WeblateOrg
Product
weblate
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-09-29T15:17:30.407Z",
  "pubdate": "2026-09-29T15:17:30.407Z",
  "executiveSummary": "Weblate versions 4.11.1 through 2026.7.1 are susceptible to an argument-injection vulnerability within the application's Mercurial (Hg) backend component.\nThe vulnerability occurs because the system fails to properly sanitize repository filenames, allowing strings starting with a hyphen (-) to be misinterpreted by the Mercurial command-line interface as command options rather than literal path arguments.\nAn authenticated user possessing 'component.edit' permissions within a project scope can leverage this flaw via the 'Update RESX files' add-on.\nSuccessful exploitation permits arbitrary command execution with the privileges of the Weblate service account, posing a critical security risk to the underlying server infrastructure.\nThis issue represents an incomplete remediation of the previously identified CVE-2022-23915, indicating that the initial control failed to account for specific malicious filename inputs.\nThe vulnerability requires authenticated access, but because it allows for full command execution, it could lead to total system compromise, unauthorized data access, and lateral movement within the hosting environment.",
  "technicalDetails": "The root cause of this vulnerability is the improper handling of repository filenames when passed as arguments to the Mercurial binary. When the application interacts with a Mercurial-backed RESX component, it executes system-level commands that construct command lines using filenames derived from user-controlled metadata.\nBecause these filenames are not sanitized or escaped (e.g., via the '--' double-hyphen separator which signals the end of command-line options), an attacker can inject arbitrary Mercurial flags. By injecting malicious options, an attacker can coerce the Mercurial process into executing external scripts or arbitrary binaries, depending on the available flags in the target Mercurial version.\nThe attack flow begins with an authenticated attacker, holding 'component.edit' privileges, creating or modifying a Mercurial-backed RESX component. The attacker crafts a repository filename that begins with a hyphen, which is designed to be interpreted as a flag by the Mercurial command-line utility. Upon the execution of the 'Update RESX files' add-on or during a standard repository synchronization update, the application backend constructs a command string containing the malicious filename.\nWhen the Mercurial backend processes this string, the shell or the Mercurial parser interprets the crafted filename as a functional switch. For example, if a filename is crafted as '-R/path/to/malicious_command', the Mercurial binary may attempt to use the injected path as an argument to a vulnerable command line switch. This leads to the invocation of commands with the effective permissions of the Weblate application service account.\nThis vulnerability is classified as an incomplete fix for CVE-2022-23915, signifying that while previous attempts to sanitize inputs were implemented, they failed to address the edge cases where hyphens at the start of filenames bypass existing validation logic. The exploitation occurs in the context of the repository update lifecycle, meaning the payload executes asynchronously when the system attempts to sync or update the component. Post-exploitation, an attacker gains the ability to execute shell commands, read/write to the filesystem, or interact with other services accessible to the Weblate service user."
}
CVE-2026-86035: Weblate Mercurial Argument Injection Vulnerability (HIGH Severity, CVSS: 8.5) | Sceawere