CVE-2026-62364

NameCVE-2026-62364
Descriptionwlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted repository, pull request checkout, or directory with untrusted ancestor configuration, it can send the token to an attacker-controlled project-configured URL. URL-scoped keys in [keys] are not affected. This issue is fixed in version 2.0.1.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wlc (PTS)bookworm1.13-2vulnerable
trixie1.15-1vulnerable
forky, sid2.0.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wlcsource(unstable)(unfixed)

Notes

https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc
https://github.com/WeblateOrg/wlc/pull/1500
https://github.com/WeblateOrg/wlc/commit/055fd2d43d0f72418b459286245330f08176db62 (2.0.1)

Search for package or bug name: Reporting problems