{"id":"PYSEC-2026-4180","summary":"wlc may disclose API tokens to project-configured URLs","details":"### Impact\n\nwlc could send an unscoped API token to an unintended server when run inside a directory tree containing attacker-controlled project configuration.\n\nIf `.weblate`, `.weblate.ini`, or `weblate.ini` defines an API url, and the user supplies a token with `WLC_KEY` or `--key` without also pinning the URL, wlc would send the token to the project-configured URL.\n\nImpacted users are those running wlc in untrusted repositories, pull request checkouts, or directories with untrusted ancestor configuration while using `WLC_KEY` or `--key`.\n\n### Patches\n\nThe issue is patched in wlc 2.0.1 via https://github.com/WeblateOrg/wlc/pull/1500.\n\nThe fix rejects unscoped keys when the API URL comes from automatically discovered project configuration:\n\n- `WLC_KEY` now requires `WLC_URL`.\n- `--key` now requires `--url`.\n- URL-scoped keys in the `[keys]` configuration section remain supported.\n\nUsers should upgrade to wlc 2.0.1 or newer.\n\n### Workarounds\n\nWithout upgrading, users can avoid the issue by explicitly pinning the API URL whenever using an unscoped key:\n\n`WLC_URL=https://hosted.weblate.org/api/ WLC_KEY=... wlc ...`\n\nor:\n\n`wlc --url https://hosted.weblate.org/api/ --key ... ...`\n\nAlternatively, use URL-scoped keys in the [keys] section instead of WLC_KEY or --key, and avoid running wlc with secrets in untrusted checkouts.\n\n- The issue was independently reported by [type5afe](https://hackerone.com/type5afe) and [visionx7](https://hackerone.com/visionx7) using HackerOne.","aliases":["CVE-2026-62364","GHSA-3mqq-hv9c-85hc"],"modified":"2026-10-01T17:45:18.544181154Z","published":"2026-10-01T16:38:34.427351Z","references":[{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc"},{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/pull/1500"},{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/commit/15cbdfc5b2c6183ef6864ea758091643a0ce6c89"},{"type":"PACKAGE","url":"https://github.com/WeblateOrg/wlc"},{"type":"WEB","url":"https://github.com/WeblateOrg/wlc/releases/tag/2.0.1"},{"type":"PACKAGE","url":"https://pypi.org/project/wlc"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3mqq-hv9c-85hc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62364"}],"affected":[{"package":{"name":"wlc","ecosystem":"PyPI","purl":"pkg:pypi/wlc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}],"versions":["0.0","0.1","0.10","0.2","0.3","0.4","0.5","0.6","0.7","0.8","0.9","1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.16.1","1.17.0","1.17.1","1.17.2","1.2","1.3","1.4","1.5","1.6","1.7","1.8","1.9","2.0.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/wlc/PYSEC-2026-4180.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N"}]}