Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xq2-fm6w-mxfm

Опубликовано: 25 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

URLs containing percent-encoded slashes (/ or \) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it.

This flaw only affects the wcurl command line tool.

URLs containing percent-encoded slashes (/ or \) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it.

This flaw only affects the wcurl command line tool.

EPSS

Процентиль: 22%
0.00302
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.6
ubuntu
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 6.5
redhat
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 4.6
nvd
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

msrc
5 месяцев назад

wcurl path traversal with percent-encoded slashes

CVSS3: 4.6
debian
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl i ...

EPSS

Процентиль: 22%
0.00302
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-22