CVE-2025-11563

Published: November 7, 2025Last modified: December 22, 2025

Description

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

Severity score breakdown

ParameterValue
Base score4.6
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScurlNot affected (8.1.0-r2)
25 LTScurlVulnerable (8.14.0-r1)
StreamcurlFixed (8.17.0-r0)
Hardened ContainersStreamcurlFixed (8.17.0-r0)

References

ON THIS PAGE