← Back

CVE-2025-11563

nvd nist
Published: Feb 25, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

Affected (1)

Products: Curl: Wcurl
1 product
Wcurl
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 2024-12-08 to 2025-11-09
Running on/withPlatform Versions
Haxx
Curl
From 8.14.0 to 8.18.0

References (4)

Source: 2499f714-1537-4658-8207-48ae4bb9eae9
PatchVendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Mailing ListPatchThird Party Advisory

Timeline

No history available yet.