cbcvebase.
CVE-2025-11563
published 2026-02-25

CVE-2025-11563: URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly…

PriorityP423medium4.6CVSS 3.1
AVNACLPRLUIRSUCLILAN
EPSS
0.02%
5.7th percentile
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

Affected

20 ranges
VendorProductVersion rangeFixed in
curlcurl8.14.0 – 8.14.0
curlcurl8.14.1 – 8.14.1
curlcurl8.15.0 – 8.15.0
curlcurl8.16.0 – 8.16.0
curlcurl8.17.0 – 8.17.0
curlwcurl>= 2024-12-08 < 2025-11-092025-11-09
debiancurl< curl 8.17.0-2 (forky)curl 8.17.0-2 (forky)
haxxcurl>= 0 < 8.14.1-2+deb13u28.14.1-2+deb13u2
haxxcurl>= 0 < 8.17.0-28.17.0-2
haxxcurl>= 0 < 7.81.0-1ubuntu1.227.81.0-1ubuntu1.22
haxxcurl>= 0 < 8.5.0-2ubuntu10.78.5.0-2ubuntu10.7
haxxcurl>= 0 < 8.14.1-2ubuntu1.18.14.1-2ubuntu1.1
haxxcurl>= 0 < 7.35.0-1ubuntu2.20+esm197.35.0-1ubuntu2.20+esm19
haxxcurl>= 0 < 7.47.0-1ubuntu2.19+esm157.47.0-1ubuntu2.19+esm15
haxxcurl>= 0 < 7.58.0-2ubuntu3.24+esm77.58.0-2ubuntu3.24+esm7
haxxcurl>= 0 < 7.68.0-1ubuntu2.25+esm27.68.0-1ubuntu2.25+esm2
msrcazl3_mysql_8.0.45-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-24_on_azure_linux_3.0
msrcazl3_rust_1.90.0-3_on_azure_linux_3.0
msrccbl2_mysql_8.0.45-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.6LOW
vendor_msrc4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.