
CVE-2025-11563 URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking f… https://www.cve.org/CVERecord?id=CVE-2025-11563
Post summary
The text discloses a directory traversal flaw in wcurl where percent‑encoded slashes allow files to be written outside the intended directory.
