MEDIUM 5.1 PyPI
wlc: print_html outputs API data without HTML escaping
GHSA-gx2m-mcc2-r4p3 · CVE-2026-42150 · PYSEC-2026-2321
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
The HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser.
Patches
Workarounds
The only vulnerable code path is HTML output which is opt-in.
References
Weblate thanks @fg0x0 for reporting this on GitHub.
References
- WEB https://github.com/WeblateOrg/wlc/security/advisories/GHSA-gx2m-mcc2-r4p3
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-42150
- WEB https://github.com/WeblateOrg/wlc/pull/1327
- WEB https://github.com/WeblateOrg/wlc/commit/0f3e58f6d7457b05d48ef40f579a172c4c8b8469
- PACKAGE https://github.com/WeblateOrg/wlc
- WEB https://github.com/WeblateOrg/wlc/releases/tag/2.0.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes