PT-2026-97036 · Weblate · Wlc

CVE-2026-62364

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

2.3

Low

VectorAV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions wlc versions prior to 2.0.1
Description The command-line client can send an unscoped API token to an attacker-controlled server when executed within an untrusted repository, pull request checkout, or a directory containing untrusted ancestor configuration. This occurs when the API URL is automatically discovered from .weblate, .weblate.ini, or weblate.ini files, while the user provides an API token via the WLC KEY environment variable or the --key parameter without specifying a matching URL. URL-scoped keys defined in the [keys] section are not affected.
Recommendations Update to version 2.0.1 or newer. As a temporary workaround, explicitly pin the API URL using WLC URL when using WLC KEY, or use the --url parameter when using --key. Use URL-scoped keys in the [keys] section instead of WLC KEY or --key. Avoid running the client with secrets in untrusted checkouts.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62364
GHSA-3MQQ-HV9C-85HC

Affected Products

Wlc