wlc could send an unscoped API token to an unintended server when run inside a directory tree containing attacker-controlled project configuration.
If .weblate, .weblate.ini, or weblate.ini defines an API url, and the user supplies a token with WLC_KEY or --key without also pinning the URL, wlc would send the token to the project-configured URL.
Impacted users are those running wlc in untrusted repositories, pull request checkouts, or directories with untrusted ancestor configuration while using WLC_KEY or --key.
The issue is patched in wlc 2.0.1 via https://github.com/WeblateOrg/wlc/pull/1500.
The fix rejects unscoped keys when the API URL comes from automatically discovered project configuration:
WLC_KEY now requires WLC_URL.--key now requires --url.[keys] configuration section remain supported.Users should upgrade to wlc 2.0.1 or newer.
Without upgrading, users can avoid the issue by explicitly pinning the API URL whenever using an unscoped key:
WLC_URL=https://hosted.weblate.org/api/ WLC_KEY=... wlc ...
or:
wlc --url https://hosted.weblate.org/api/ --key ... ...
Alternatively, use URL-scoped keys in the [keys] section instead of WLC_KEY or --key, and avoid running wlc with secrets in untrusted checkouts.
{
"cwe_ids": [
"CWE-200",
"CWE-349"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-22T20:34:07Z",
"nvd_published_at": null,
"severity": "LOW"
}