VDB
EN
MEDIUM 4.6

GHSA-6wxc-8mgq-w26m

Weblate: Stored HTML injection in editor search preview

상세

### Impact Weblate's live search preview renders unit `source` and `context` as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search.

### Patches * https://github.com/WeblateOrg/weblate/pull/19422

### Workarounds Only the search preview on the selected views is affected.

### Resources Weblate thanks @adrgs for reporting this issue responsibly via GitHub.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / weblate
최초 영향 버전: 0 수정 버전: 2026.5
수정 pip install --upgrade 'weblate>=2026.5'

참고