Path traversal in WeeChat - #VU147393

 

Path traversal in WeeChat - #VU147393

Published: September 8, 2026


Vulnerability identifier: #VU147393
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write files outside the configured download path.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in the xfer DCC file download handling when receiving a DCC file with a filename containing a non-native directory separator. A remote attacker can send a crafted DCC file to write files outside the configured download path.

User interaction is required to receive the DCC file.


Affected software

WeeChat

Remediation

Install security update from vendor's website.

WeeChat - update to 4.10.1

External References

Related Security Bulletins