MEDIUM 4.6
GHSA-6wxc-8mgq-w26m
Weblate: Stored HTML injection in editor search preview
Details
### Impact Weblate's live search preview renders unit `source` and `context` as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search.
### Patches * https://github.com/WeblateOrg/weblate/pull/19422
### Workarounds Only the search preview on the selected views is affected.
### Resources Weblate thanks @adrgs for reporting this issue responsibly via GitHub.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-6wxc-8mgq-w26m [WEB]
- https://github.com/WeblateOrg/weblate/pull/19422 [WEB]
- https://github.com/WeblateOrg/weblate/commit/8b0adf1d0b43dfc0d09da4b878857b2288b84f2d [WEB]
- https://github.com/WeblateOrg/weblate [PACKAGE]
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.5 [WEB]