{"schema_version":"1.9.0","id":"CVE-2025-11563","published":"2026-02-25T07:20:47.012Z","modified":"2026-08-12T03:51:45.109134777Z","related":["SUSE-SU-2025:21077-1","SUSE-SU-2025:21145-1","SUSE-SU-2025:21198-1","SUSE-SU-2025:21206-1","SUSE-SU-2025:4180-1","SUSE-SU-2025:4236-1","SUSE-SU-2025:4300-1","SUSE-SU-2025:4309-1","openSUSE-SU-2025:15757-1","openSUSE-SU-2025:20090-1"],"summary":"wcurl path traversal with percent-encoded slashes","details":"URLs containing percent-encoded slashes (`/` or `\\`) can trick wcurl into\nsaving the output file outside of the current directory without the user\nexplicitly asking for it.\n\nThis flaw only affects the wcurl command line tool.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/curl/wcurl","events":[{"introduced":"46c323d9a2ff40c0ef4b25cce74f1f74bec1dcd7"},{"fixed":"f925904ddcd97b9c4e6473b50291414ced8675ce"}],"database_specific":{"cpe":"cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2024-12-08"},{"fixed":"2025-11-09"}],"source":"CPE_RANGE"}}],"versions":["v2025.11.04","v2025.09.27","v2025.05.26","v2025.04.20","v2025.02.24","v2024.12.08"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11563.json"}}],"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/11/04/1"},{"type":"WEB","url":"https://curl.se/docs/CVE-2025-11563.html"},{"type":"WEB","url":"https://curl.se/docs/CVE-2025-11563.json"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11563.json"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-release/2025/11/msg00504.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11563"}],"database_specific":{"cna_assigner":"curl","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11563.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.17.0"},{"last_affected":"8.17.0"},{"introduced":"8.16.0"},{"last_affected":"8.16.0"},{"introduced":"8.15.0"},{"last_affected":"8.15.0"},{"introduced":"8.14.1"},{"last_affected":"8.14.1"},{"introduced":"8.14.0"},{"last_affected":"8.14.0"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}]}