Weblate (a web-based localization tool) prior to 5.16.0 contains an input validation flaw in the SSH management console when adding an SSH host key. The console does not validate the user-supplied input passed to the underlying ssh-add invocation, enabling argument injection into ssh-add. This could allow an attacker to influence the behavior of ssh-add by supplying crafted arguments via the host key input path. The issue is fixed in Weblate 5.16.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
ssh-add, potentially altering SSH key handling behavior and impacting the integrity of SSH key management operations performed by Weblate.If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC for CVE-2026-24126 affecting self-hosted Weblate. It contains two files: a Python exploit script (CVE-2026-24126.py) and a README documenting the vulnerability, affected versions, root cause, usage, and remediation. The exploit is not part of a larger framework. The Python script performs an authenticated web attack against Weblate’s SSH key management feature. It first creates a requests session, fetches /accounts/login/ to obtain a CSRF token, and submits administrator credentials. If login succeeds, it requests the main page to extract another CSRF token, then sends a POST request to /manage/ssh/ with the host parameter set to a crafted value of the form -f<file>. This abuses Weblate’s unsafe passing of the host field to ssh-keyscan, causing ssh-keyscan to interpret the attacker-controlled value as its -f option and read hostnames from an arbitrary local file on the server. The exploit’s main capability is arbitrary file read as the Weblate service account. It does not provide code execution, persistence, or lateral movement. After the POST request, the script parses the returned HTML using BeautifulSoup, locates the alert-danger block, and uses regex patterns to recover leaked file lines from ssh-keyscan error messages such as getaddrinfo, write, and connect failures. The extracted lines are deduplicated and printed to stdout. Repository structure is minimal and purpose-built: one executable Python entry point with login, exploit, and response parsing logic, plus documentation. The code uses requests, argparse, regex, BeautifulSoup, and disables TLS verification warnings. A localhost proxy entry is present for debugging, but it is not actually passed into requests calls. Overall, this is a real operational PoC for authenticated arbitrary file disclosure against vulnerable Weblate instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.