September 5, 2026
- Weblate's
wlcCLI can be made to leak an API token: it discovers the API URL from a config file it finds on disk, so an attacker-supplied config plus$WLC_KEYsends the token to a server of the attacker's choosing, exposing translation repos and workflows (HackerOne). · Supply Chain & Build Pipelines
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May