wlc may disclose API tokens to project-configured URLs
Summary
| CVE | CVE-2026-62364 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-22 21:17:30 UTC |
| Updated | 2026-09-26 01:17:01 UTC |
| Description | wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted repository, pull request checkout, or directory with untrusted ancestor configuration, it can send the token to an attacker-controlled project-configured URL. URL-scoped keys in [keys] are not affected. This issue is fixed in version 2.0.1. |
Risk And Classification
Primary CVSS: v3.1 2.3 LOW from [email protected]
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
EPSS: 0.000800000 probability, percentile 0.001590000 (date 2026-09-27)
Problem Types: CWE-200 | CWE-349 | CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | CWE-349 CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 2.3 | LOW | CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N |
| 3.1 | CNA | DECLARED | 2.3 | LOW | CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
HighUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WeblateOrg | Wlc | affected < 2.0.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/WeblateOrg/wlc/releases/tag/2.0.1 | [email protected] | github.com | |
| github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc | [email protected] | github.com | |
| github.com/WeblateOrg/wlc/commit/15cbdfc5b2c6183ef6864ea758091643a0ce6c89 | [email protected] | github.com | |
| github.com/WeblateOrg/wlc/pull/1500 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.