CVE-2026-62364 Overview
CVE-2026-62364 is an information disclosure vulnerability [CWE-200] in wlc, the Weblate command-line client that uses Weblate's REST API. Versions prior to 2.0.1 automatically load configuration from .weblate, .weblate.ini, or weblate.ini files, which can select the API URL used for requests. When an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url, wlc may transmit that token to an attacker-controlled URL declared in project configuration. The issue is fixed in version 2.0.1.
Critical Impact
An unscoped Weblate API token can be sent to an attacker-controlled endpoint when wlc runs inside an untrusted repository or a directory with untrusted ancestor configuration.
Affected Products
- Weblate wlc command-line client versions prior to 2.0.1
- Environments using WLC_KEY environment variable without WLC_URL
- Environments invoking wlc --key without --url
Discovery Timeline
- 2026-09-22 - CVE-2026-62364 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-62364
Vulnerability Analysis
The wlc client discovers configuration automatically from .weblate, .weblate.ini, or weblate.ini files located in the current directory or its ancestors. This discovered configuration can define the API URL that wlc uses for outbound REST requests. When a user supplies an unscoped API token through WLC_KEY or --key, the client attaches that token to requests directed at whichever URL the auto-discovered configuration selects.
The result is that a repository controlled by an attacker can dictate the destination for a legitimate user's API token. Untrusted ancestor directories, pull request checkouts, and shared build workspaces all present opportunities for hostile configuration files to be present. Keys declared with an explicit URL binding in the [keys] section are not affected because the token is scoped to a specific endpoint.
Root Cause
The root cause is missing coupling between credential material and destination URL. wlc treated the API token and the API URL as independent inputs, allowing one to come from a trusted source (environment or CLI) while the other came from untrusted on-disk configuration. This design allowed configuration precedence to override the assumption that a user-supplied credential is intended for a user-controlled endpoint.
Attack Vector
Exploitation requires local access and a specific set of conditions, including user interaction with a repository or directory that contains a hostile .weblate configuration file. An attacker who can plant such a configuration in a pull request, a shared workspace, or any ancestor directory of the working path can redirect wlc API traffic. When the victim then invokes wlc with WLC_KEY or --key set but no matching URL, the client sends the token to the attacker-defined URL.
The fix, applied in version 2.0.1, requires explicit URL pinning whenever an unscoped API key is provided:
2.0.1
-----
* Released on 26th June 2026.
* Require explicit URL pinning for unscoped API keys when the API URL comes
from automatically discovered project configuration: ``WLC_KEY`` requires
``WLC_URL`` and ``--key`` requires ``--url``.
Source: GitHub Commit 15cbdfc
Detection Methods for CVE-2026-62364
Indicators of Compromise
- Unexpected outbound HTTPS requests from developer or CI hosts to non-Weblate domains carrying an Authorization: Token header.
- Presence of .weblate, .weblate.ini, or weblate.ini files in repositories, pull request branches, or ancestor directories that reference third-party or unfamiliar API URLs.
- Weblate audit logs showing API tokens being used from unexpected client IP addresses after suspected exposure.
Detection Strategies
- Scan source repositories and build workspaces for wlc configuration files that set a url value pointing outside your Weblate deployment.
- Inventory environments where WLC_KEY is exported without a companion WLC_URL, and where wlc --key is invoked without --url.
- Correlate CI/CD job logs with outbound network telemetry to identify wlc executions that contacted unexpected hosts.
Monitoring Recommendations
- Alert on egress from CI runners to any host not on an allowlist of approved Weblate API endpoints.
- Monitor Weblate server logs for token use from new source addresses following execution of wlc in untrusted directories.
- Track version banners of installed wlc packages across developer workstations and CI images to confirm remediation coverage.
How to Mitigate CVE-2026-62364
Immediate Actions Required
- Upgrade wlc to version 2.0.1 or later on every workstation, container image, and CI runner.
- Rotate any Weblate API tokens that may have been used with wlc in untrusted repositories or shared directories.
- Audit repositories and build artifacts for unauthorized .weblate, .weblate.ini, and weblate.ini files.
Patch Information
The fix is available in wlc version 2.0.1, released 26 June 2026. See the GitHub Release v2.0.1, the GitHub Security Advisory GHSA-3mqq-hv9c-85hc, and the corresponding Pull Request #1500. After patching, WLC_KEY requires WLC_URL, and --key requires --url, whenever the API URL would otherwise be sourced from auto-discovered configuration.
Workarounds
- Use URL-scoped tokens declared in the [keys] section of a trusted configuration file, which are not affected by this issue.
- Always pair WLC_KEY with WLC_URL, and --key with --url, to pin the destination of the token explicitly.
- Avoid running wlc inside untrusted repositories, pull request checkouts, or directories with ancestor configuration you do not control.
# Configuration example: pin URL explicitly when using unscoped keys
export WLC_URL="https://weblate.example.com/api/"
export WLC_KEY="your-weblate-api-token"
# Or on the command line
wlc --url https://weblate.example.com/api/ --key your-weblate-api-token list-projects
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
