Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rp8-h4g8-8766

Опубликовано: 12 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Weblate wlc has insecure API key configuration

Impact

Historically, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be used against different server.

Patches

Workarounds

Remove unscoped key from wlc configuration. Only use URL-scoped keys in the [keys] sections.

References

This issue was reported to us by wh1zee via HackerOne.

Пакеты

Наименование

wlc

pip
Затронутые версииВерсия исправления

< 1.17.0

1.17.0

EPSS

Процентиль: 1%
0.00011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-922

Связанные уязвимости

CVSS3: 5.3
ubuntu
8 дней назад

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

CVSS3: 5.3
nvd
8 дней назад

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

CVSS3: 5.3
debian
8 дней назад

wlc is a Weblate command-line client using Weblate's REST API. Prior t ...

EPSS

Процентиль: 1%
0.00011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-922