VDB
KO
MEDIUM 4.6

GHSA-6wxc-8mgq-w26m

Weblate: Stored HTML injection in editor search preview

Details

### Impact Weblate's live search preview renders unit `source` and `context` as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search.

### Patches * https://github.com/WeblateOrg/weblate/pull/19422

### Workarounds Only the search preview on the selected views is affected.

### Resources Weblate thanks @adrgs for reporting this issue responsibly via GitHub.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / weblate
Introduced in: 0 Fixed in: 2026.5
Fix pip install --upgrade 'weblate>=2026.5'

References