Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11563

Опубликовано: 25 фев. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

URLs containing percent-encoded slashes (/ or \) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

A flaw was found in wcurl. This vulnerability allows a remote attacker to manipulate the location where output files are saved. By crafting a malicious URL with percent-encoded slashes, the attacker can trick the wcurl command-line tool into writing files outside of the intended directory. This could lead to unauthorized file placement on the system.

Отчет

Note: this vulnerability only affects the wcurl command line tool.

Меры по смягчению последствий

Some potential mitigations to limit the risk of this vulnerability include:

  1. Explicitly choose an output filename with -o/-O/--output
  2. Disable percent-decoding for output filenames with --no-decode-filename.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2442571wcurl: wcurl: Arbitrary file placement via crafted URLs

EPSS

Процентиль: 23%
0.00302
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.6
ubuntu
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 4.6
nvd
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

msrc
5 месяцев назад

wcurl path traversal with percent-encoded slashes

CVSS3: 4.6
debian
5 месяцев назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl i ...

suse-cvrf
8 месяцев назад

Security update for curl

EPSS

Процентиль: 23%
0.00302
Низкий

6.5 Medium

CVSS3