Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 53.0%