Hi, The following vulnerability was published for wlc. CVE-2026-62364[0]: | wlc is a Weblate command-line client using Weblate's REST API. Prior | to 2.0.1, automatically discovered configuration from .weblate, | .weblate.ini, or weblate.ini can select the API URL while an | unscoped API token is supplied through WLC_KEY or --key without a | matching WLC_URL or --url. When wlc runs in an untrusted repository, | pull request checkout, or directory with untrusted ancestor | configuration, it can send the token to an attacker-controlled | project-configured URL. URL-scoped keys in [keys] are not affected. | This issue is fixed in version 2.0.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-62364 https://www.cve.org/CVERecord?id=CVE-2026-62364 [1] https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc [2] https://github.com/WeblateOrg/wlc/pull/1500 [3] https://github.com/WeblateOrg/wlc/commit/055fd2d43d0f72418b459286245330f08176db62 Please adjust the affected versions in the BTS as needed. Regards, Salvatore