DEBIAN-CVE-2025-11563
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 25 Feb 2026, 08:16
Last modified:15 Jun 2026, 19:05
Vulnerability Summary
Overall Risk (default)
low
18/100 CVSS Score
4.6 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
25 Feb 2026, 08:16
Published
Vulnerability first disclosed
15 Jun 2026, 19:05
Last Modified
Vulnerability information updated
Description
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.6CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected Systems
- debian•curl
< 8.14.1-2+deb13u2 | < 8.17.0-2