URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into
saving the output file outside of the current directory without the user
explicitly asking for it.
This flaw only affects the wcurl command line tool.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool. | |
| Title | wcurl path traversal with percent-encoded slashes | |
| References |
|
Status: PUBLISHED
Assigner: curl
Published:
Updated: 2026-02-25T07:24:31.792Z
Reserved: 2025-10-09T13:50:54.563Z
Link: CVE-2025-11563
No data.
Status : Awaiting Analysis
Published: 2026-02-25T08:16:18.337
Modified: 2026-02-25T14:15:29.980
Link: CVE-2025-11563
No data.
OpenCVE Enrichment
No data.