CVE-2025-69194

Source
https://cve.org/CVERecord?id=CVE-2025-69194
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69194.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-69194
Downstream
Related
Published
2026-01-09T07:53:48.144Z
Modified
2026-07-15T01:48:56.587591262Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Wget2: arbitrary file write via metalink path traversal in gnu wget2
Details

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "fedora",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69194.json"
}
References

Affected packages

Git / gitlab.com/gnuwget/wget2

Affected ranges

Type
GIT
Repo
https://gitlab.com/gnuwget/wget2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.99.2
v2.*
v2.0.0
v2.0.1
v2.1.0
v2.2.0
wget2-1.*
wget2-1.99.0
wget2-1.99.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69194.json"