Path traversal in WeeChat - #VU147393
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to write files outside the configured download path.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the xfer DCC file download handling when receiving a DCC file with a filename containing a non-native directory separator. A remote attacker can send a crafted DCC file to write files outside the configured download path.
User interaction is required to receive the DCC file.