CVE-2025-11563
Moderate
wcurl path traversal with percent-encoded slashes
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
Exploit probability
0.3%
Published
February 25, 2026
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-11563
View original source
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2025/11/04/1
- https://curl.se/docs/CVE-2025-11563.html
- https://curl.se/docs/CVE-2025-11563.json
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11563.json
- https://lists.debian.org/debian-release/2025/11/msg00504.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-11563