← Back

CVE-2025-69194

nvd nist
Published: Jan 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.

Affected (1)

Products: Gnu: Wget2
1 product
Wget2
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.2.1

References (2)

Source: patrick@puiterwijk.org
Third Party Advisory
Source: patrick@puiterwijk.org
Issue TrackingThird Party Advisory

Timeline

No history available yet.