Path traversal in cURL and wcurl - CVE-2026-80256
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to create a new file outside the intended directory.
The vulnerability exists due to path traversal in wcurl output filename handling when decoding percent-encoded backslashes on Windows. A remote attacker can provide a crafted filename to create a new file outside the intended directory.
The new file is subject to the user's filesystem permissions, the target file must not already exist, and this issue affects only Windows.
Affected software
wcurl
How to mitigate CVE-2026-80256
wcurl - update to 2026.08.30