← Back

CVE-2025-11563

nvd nist
Published: Feb 25, 2026Modified: Feb 26, 2026

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

Affected (1)

Products: Curl: Wcurl
1 product
Wcurl
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 2024-12-08 to 2025-11-09
Running on/withPlatform Versions
Haxx
Curl
From 8.14.0 to 8.18.0

References (4)

Source: 2499f714-1537-4658-8207-48ae4bb9eae9
PatchVendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Mailing ListThird Party AdvisoryPatch

Timeline

No history available yet.