WeeChat 4.9.4 fixes two serious relay and logger vulnerabilities
Updated July 22, 2026
An emergency security release: WeeChat shipped 4.9.4 today. Two issues, both nasty in the right setup:
- Relay authentication bypass — affects the "api" and "weechat" relay protocols. If your WeeChat accepts relay connections, an attacker could get in without valid credentials.
- Logger path traversal — log filenames could escape the log directory.
The relay bug is the one to move on. The relay is how phones and web frontends attach to a running WeeChat, so the people exposed are precisely the ones running always-on setups on public servers.
Update: your package manager, or weechat.org/download. Details in the release announcement.
If you cannot update today, close the relay port until you can.