#1148878 wlc: CVE-2026-62364

Package:
src:wlc
Source:
src:wlc
Submitter:
Salvatore Bonaccorso
Date:
2026-09-28 17:37:10 UTC
Severity:
normal
Tags:
#1148878#5
Date:
2026-09-24 14:47:19 UTC
From:
To:
Hi,

The following vulnerability was published for wlc.

CVE-2026-62364[0]:
| wlc is a Weblate command-line client using Weblate's REST API. Prior
| to 2.0.1, automatically discovered configuration from .weblate,
| .weblate.ini, or weblate.ini can select the API URL while an
| unscoped API token is supplied through WLC_KEY or --key without a
| matching WLC_URL or --url. When wlc runs in an untrusted repository,
| pull request checkout, or directory with untrusted ancestor
| configuration, it can send the token to an attacker-controlled
| project-configured URL. URL-scoped keys in [keys] are not affected.
| This issue is fixed in version 2.0.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-62364
https://www.cve.org/CVERecord?id=CVE-2026-62364
[1] https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc
[2] https://github.com/WeblateOrg/wlc/pull/1500
[3] https://github.com/WeblateOrg/wlc/commit/055fd2d43d0f72418b459286245330f08176db62

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore