CVE-2026-62364

low

Description

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted repository, pull request checkout, or directory with untrusted ancestor configuration, it can send the token to an attacker-controlled project-configured URL. URL-scoped keys in [keys] are not affected. This issue is fixed in version 2.0.1.

References

https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc

https://github.com/WeblateOrg/wlc/releases/tag/2.0.1

https://github.com/WeblateOrg/wlc/pull/1500

https://github.com/WeblateOrg/wlc/commit/15cbdfc5b2c6183ef6864ea758091643a0ce6c89

Details

Source: Mitre, NVD

Published: 2026-09-22

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 0.8

Vector: CVSS2#AV:L/AC:H/Au:M/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 2.3

Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00098