Security Advisory

CVE-2025-11563

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-02-25 07:20:47
Last updated 2026-02-25 18:53:58
Assigner curl
CVSS score not scored
State PUBLISHED

Description

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.