CVE-2026-62364

Source
https://cve.org/CVERecord?id=CVE-2026-62364
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62364.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-62364
Aliases
Downstream
Published
2026-09-22T20:17:06Z
Modified
2026-09-24T03:45:40Z
Severity
  • 2.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N CVSS Calculator
Summary
wlc may disclose API tokens to project-configured URLs
Details

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted repository, pull request checkout, or directory with untrusted ancestor configuration, it can send the token to an attacker-controlled project-configured URL. URL-scoped keys in [keys] are not affected. This issue is fixed in version 2.0.1.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-200",
        "CWE-349"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62364.json"
}
References

Affected packages

Git / github.com/weblateorg/wlc

Affected ranges

Type
GIT
Repo
https://github.com/weblateorg/wlc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.0.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1
0.10
0.2
0.3
0.4
0.5
0.6
0.7
0.8
0.9
1.*
1.0
1.1
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.16.1
1.17.0
1.17.1
1.17.2
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
2.*
2.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62364.json"