MEDIUM 5.3 PyPI

Weblate wlc has insecure API key configuration

GHSA-9rp8-h4g8-8766 · CVE-2026-22251 · PYSEC-2026-2052

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Historically, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be used against different server.

Patches

Workarounds

Remove unscoped key from wlc configuration. Only use URL-scoped keys in the [keys] sections.

References

This issue was reported to us by wh1zee via HackerOne.

Ready to move

Start Securing

Free, no credit card | First findings in minutes