Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11563

Опубликовано: 25 фев. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

URLs containing percent-encoded slashes (/ or \) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

A flaw was found in wcurl. This vulnerability allows a remote attacker to manipulate the location where output files are saved. By crafting a malicious URL with percent-encoded slashes, the attacker can trick the wcurl command-line tool into writing files outside of the intended directory. This could lead to unauthorized file placement on the system.

Отчет

Note: this vulnerability only affects the wcurl command line tool.

Меры по смягчению последствий

Some potential mitigations to limit the risk of this vulnerability include:

  1. Explicitly choose an output filename with -o/-O/--output
  2. Disable percent-decoding for output filenames with --no-decode-filename.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2442571wcurl: wcurl: Arbitrary file placement via crafted URLs

EPSS

Процентиль: 6%
0.00023
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.6
ubuntu
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 4.6
nvd
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

msrc
около 1 месяца назад

wcurl path traversal with percent-encoded slashes

CVSS3: 4.6
debian
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl i ...

suse-cvrf
4 месяца назад

Security update for curl

EPSS

Процентиль: 6%
0.00023
Низкий

6.5 Medium

CVSS3