PT-2026-97036 · Weblate · Wlc
CVE-2026-62364
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
2.3
Low
| Vector | AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
wlc versions prior to 2.0.1
Description
The command-line client can send an unscoped API token to an attacker-controlled server when executed within an untrusted repository, pull request checkout, or a directory containing untrusted ancestor configuration. This occurs when the API URL is automatically discovered from
.weblate, .weblate.ini, or weblate.ini files, while the user provides an API token via the WLC KEY environment variable or the --key parameter without specifying a matching URL. URL-scoped keys defined in the [keys] section are not affected.Recommendations
Update to version 2.0.1 or newer.
As a temporary workaround, explicitly pin the API URL using
WLC URL when using WLC KEY, or use the --url parameter when using --key.
Use URL-scoped keys in the [keys] section instead of WLC KEY or --key.
Avoid running the client with secrets in untrusted checkouts.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wlc