Command-Line Client Vulnerability in Weblate Affected by Unscoped API Token Issue
CVE-2026-62364

2.3LOW

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-62364?

The Weblate command-line client, wlc, has a vulnerability that allows an unscoped API token to be exposed when the tool is run in untrusted environments. This situation arises when configurations from certain files such as .weblate or .weblate.ini are used to set the API URL without proper scoping of the token. This can lead to attackers gaining access to sensitive resources if wlc is executed in a compromised repository or directory. It is important for users to update to version 2.0.1 to mitigate this risk.

Affected Version(s)

wlc < 2.0.1

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.