CVE-2026-86035 Weblate Mercurial 参数注入漏洞
影响攻击者可以 Weblate 服务账户权限执行任意命令
Weblate 是基于 Web 的持续本地化平台,用于管理软件翻译。其 Mercurial 后端存在参数注入漏洞,仓库文件名以 - 开头时会被当作 Mercurial 选项而非路径处理。该漏洞是 CVE-2022-23915 修复不完整导致的残留问题。
影响范围
Weblate 4.11.1 至 2026.7.1 版本受影响,官方已在 2026.8 版本中修复。
漏洞详情
漏洞类型为参数注入。Mercurial 后端在处理以 - 开头的仓库文件名时,未将其与命令行选项区分,导致文件名被解释为 Mercurial 参数。拥有项目级 component.edit 权限的已认证用户,可通过使用 Update RESX files 插件的 Mercurial 后端 RESX 组件触发该问题,后续仓库更新时即可执行任意命令。
利用条件与风险
利用需要攻击者已认证并具备项目级 component.edit 权限,且目标使用 Mercurial 后端与 RESX 组件。成功利用后可以 Weblate 服务账户权限执行任意命令,风险较高。
修复建议
官方已在 Weblate 2026.8 版本中修复,建议尽快升级。临时缓解措施暂无公开信息。
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with – could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.