« Volver al listado

CVE-2025-11563

Estado: AnalizadaMedia (4.6)—

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it.

This flaw only affects the wcurl command line tool.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-11563",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-11563",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-25T18:53:51.461545Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9",
      "affectedData": [
        {
          "vendor": "curl",
          "product": "curl",
          "versions": [
            {
              "status": "affected",
              "version": "8.17.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.17.0"
            },
            {
              "status": "affected",
              "version": "8.16.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.16.0"
            },
            {
              "status": "affected",
              "version": "8.15.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.15.0"
            },
            {
              "status": "affected",
              "version": "8.14.1",
              "versionType": "semver",
              "lessThanOrEqual": "8.14.1"
            },
            {
              "status": "affected",
              "version": "8.14.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.14.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-25T08:16:18.337",
  "references": [
    {
      "url": "https://curl.se/docs/CVE-2025-11563.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://curl.se/docs/CVE-2025-11563.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/11/04/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-release/2025/11/msg00504.html",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "URLs containing percent-encoded slashes (`/` or `\\`) can trick wcurl into\nsaving the output file outside of the current directory without the user\nexplicitly asking for it.\n\nThis flaw only affects the wcurl command line tool."
    },
    {
      "lang": "es",
      "value": "Las URL que contienen barras codificadas por porcentaje ('/' o '\\') pueden engañar a wcurl para que guarde el archivo de salida fuera del directorio actual sin que el usuario lo solicite explícitamente.\n\nEste fallo solo afecta a la herramienta de línea de comandos wcurl."
    }
  ],
  "lastModified": "2026-06-17T08:30:42.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E74B21B-AEC7-4FE3-AF2D-E30036CF6B49",
              "versionEndExcluding": "2025-11-09",
              "versionStartIncluding": "2024-12-08"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7DBCC6EF-C6A7-4AB4-96CA-A72C6F264D26",
              "versionEndExcluding": "8.18.0",
              "versionStartIncluding": "8.14.0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "2499f714-1537-4658-8207-48ae4bb9eae9"
}