A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.
History

Fri, 09 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu wget
Vendors & Products Gnu
Gnu wget

Fri, 09 Jan 2026 08:00:00 +0000

Type Values Removed Values Added
Title wget2: Arbitrary File Write via Metalink Path Traversal in GNU Wget2 Wget2: arbitrary file write via metalink path traversal in gnu wget2
References

Tue, 30 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
Description A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.
Title wget2: Arbitrary File Write via Metalink Path Traversal in GNU Wget2
Weaknesses CWE-22
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2026-01-09T07:53:48.144Z

Updated: 2026-01-10T04:55:45.399Z

Reserved: 2025-12-29T13:49:33.180Z

Link: CVE-2025-69194

cve-icon Vulnrichment

Updated: 2026-01-09T13:50:37.185Z

cve-icon NVD

Status : Received

Published: 2026-01-09T08:15:57.980

Modified: 2026-01-09T08:15:57.980

Link: CVE-2025-69194

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-29T00:00:00Z

Links: CVE-2025-69194 - Bugzilla