CVE-2025-11563
Last modified
CVE-2025-11563 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Curl | Wcurl | >= 2024-12-08, < 2025-11-09 |
References
- https://curl.se/docs/CVE-2025-11563.htmlPatch, Vendor Advisory
- https://curl.se/docs/CVE-2025-11563.jsonVendor Advisory
- http://www.openwall.com/lists/oss-security/2025/11/04/1Mailing List, Third Party Advisory
- https://lists.debian.org/debian-release/2025/11/msg00504.htmlMailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11563?
How severe is CVE-2025-11563?
How do I fix CVE-2025-11563?
Are you affected by CVE-2025-11563?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
