{"id":"GHSA-3mqq-hv9c-85hc","summary":"wlc may disclose API tokens to project-configured URLs","details":"### Impact\n\nwlc could send an unscoped API token to an unintended server when run inside a directory tree containing attacker-controlled project configuration.\n\nIf `.weblate`, `.weblate.ini`, or `weblate.ini` defines an API url, and the user supplies a token with `WLC_KEY` or `--key` without also pinning the URL, wlc would send the token to the project-configured URL.\n\nImpacted users are those running wlc in untrusted repositories, pull request checkouts, or directories with untrusted ancestor configuration while using `WLC_KEY` or `--key`.\n\n### Patches\n\nThe issue is patched in wlc 2.0.1 via https://github.com/WeblateOrg/wlc/pull/1500.\n\nThe fix rejects unscoped keys when the API URL comes from automatically discovered project configuration:\n\n- `WLC_KEY` now requires `WLC_URL`.\n- `--key` now requires `--url`.\n- URL-scoped keys in the `[keys]` configuration section remain supported.\n\nUsers should upgrade to wlc 2.0.1 or newer.\n\n### Workarounds\n\nWithout upgrading, users can avoid the issue by explicitly pinning the API URL whenever using an unscoped key:\n\n`WLC_URL=https://hosted.weblate.org/api/ WLC_KEY=... wlc ...`\n\nor:\n\n`wlc --url https://hosted.weblate.org/api/ --key ... ...`\n\nAlternatively, use URL-scoped keys in the [keys] section instead of WLC_KEY or --key, and avoid running wlc with secrets in untrusted checkouts.\n\n- The issue was independently reported by [type5afe](https://hackerone.com/type5afe) and [visionx7](https://hackerone.com/visionx7) using HackerOne.","aliases":["CVE-2026-62364","PYSEC-2026-4180"],"modified":"2026-10-01T17:55:48.637660417Z","published":"2026-09-22T20:34:07Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200","CWE-349"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:34:07Z"},"references":[{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc"},{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/pull/1500"},{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/commit/15cbdfc5b2c6183ef6864ea758091643a0ce6c89"},{"type":"PACKAGE","url":"https://github.com/WeblateOrg/wlc"},{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/releases/tag/2.0.1"}],"affected":[{"package":{"name":"wlc","ecosystem":"PyPI","purl":"pkg:pypi/wlc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}],"versions":["0.0","0.1","0.10","0.2","0.3","0.4","0.5","0.6","0.7","0.8","0.9","1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.16.1","1.17.0","1.17.1","1.17.2","1.2","1.3","1.4","1.5","1.6","1.7","1.8","1.9","2.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3mqq-hv9c-85hc/GHSA-3mqq-hv9c-85hc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N"}]}