
OtherCVSS 6.6€0
Argument Injection in /manage/ssh/ via host parameter leads to sensitive file disclosure on Weblate
alexb_616
Disclosed on HackerOne · April 26, 2026
Publicly disclosed report · by alexb_616
View original on HackerOneDescribe the security issue you would like to report
Product: Weblate. Verified on self-hosted instances. Affected Versions: Confirmed in version 5.0.2 and the current stable release 5.15.2. Probably all versions are vulnerable.
A critical argument injection vulnerability was discovered in the SSH management interface. The host parameter does not properly sanitize user input before passing it to internal system commands. An attacker with administrative privileges can inject command-line arguments (such as -f) to force the server to read and display the contents of sensitive local files, including /etc/passwd, Django settings.py (containing the SECRET_KEY), and private SSH keys (id_rsa).
Endpoint: /manage/ssh/