CVE-2025-11563

MEDIUM

wcurl 2024-12-08-2025-11-09 - Path Traversal via Percent-Encoded Slashes

Title source: llm
STIX 2.1

Description

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

Scores

CVSS v3 4.6
EPSS 0.0030
EPSS Percentile 21.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
curl/wcurl 2024-12-08 - 2025-11-09
Published Feb 25, 2026
Tracked Since Feb 25, 2026