CVE-2025-11563

Published Feb 25, 2026

Last updated 6 days ago

Overview

Description
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
Source
2499f714-1537-4658-8207-48ae4bb9eae9
NVD status
Analyzed
Products
wcurl

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.6
Impact score
2.5
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-22

Social media

Hype score
Not currently trending

Configurations