天下漏洞,尽知其名
HIGH

CVE-2026-86035 Weblate Mercurial 参数注入漏洞

影响攻击者可以 Weblate 服务账户权限执行任意命令

AI 研判

Weblate 是基于 Web 的持续本地化平台,用于管理软件翻译。其 Mercurial 后端存在参数注入漏洞,仓库文件名以 - 开头时会被当作 Mercurial 选项而非路径处理。该漏洞是 CVE-2022-23915 修复不完整导致的残留问题。

影响范围

Weblate

Weblate 4.11.1 至 2026.7.1 版本受影响,官方已在 2026.8 版本中修复。

漏洞详情

漏洞类型为参数注入。Mercurial 后端在处理以 - 开头的仓库文件名时,未将其与命令行选项区分,导致文件名被解释为 Mercurial 参数。拥有项目级 component.edit 权限的已认证用户,可通过使用 Update RESX files 插件的 Mercurial 后端 RESX 组件触发该问题,后续仓库更新时即可执行任意命令。

利用条件与风险

利用需要攻击者已认证并具备项目级 component.edit 权限,且目标使用 Mercurial 后端与 RESX 组件。成功利用后可以 Weblate 服务账户权限执行任意命令,风险较高。

修复建议

官方已在 Weblate 2026.8 版本中修复,建议尽快升级。临时缓解措施暂无公开信息。

原始情报

Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with – could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.