CVE-2026-62364Low· 2.3▾ Sunlitwlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted repository, pull request checkout, or directory with untrusted ancestor configuration, it can send the token to an attacker-controlled project-configured URL. URL-scoped keys in [keys] are not affected. This issue is fixed in version 2.0.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
wlc < 2.0.1Patched in:
wlc 2.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42150Medium· 5.1wlc: print_html outputs API data without HTML escaping
CVE-2026-23535High· 8.0Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
CVE-2026-22251Medium· 5.3Weblate wlc has insecure API key configuration
CVE-2026-22250Low· 2.5Weblate command-line client susceptible to SSL verification skip
CVE-2026-48828Medium· 6.5The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…