ircbits.com

Index / WeeChat 4.9.4 fixes two serious relay and logger vulnerabilities

WeeChat 4.9.4 fixes two serious relay and logger vulnerabilities

Updated July 22, 2026

An emergency security release: WeeChat shipped 4.9.4 today. Two issues, both nasty in the right setup:

  • Relay authentication bypass — affects the "api" and "weechat" relay protocols. If your WeeChat accepts relay connections, an attacker could get in without valid credentials.
  • Logger path traversal — log filenames could escape the log directory.

The relay bug is the one to move on. The relay is how phones and web frontends attach to a running WeeChat, so the people exposed are precisely the ones running always-on setups on public servers.

Update: your package manager, or weechat.org/download. Details in the release announcement.

If you cannot update today, close the relay port until you can.