CVE-2025-69194

A

security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.

References
Link Resource
https://access.redhat.com/security/cve/CVE-2025-69194 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2425773 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:wget2:*:*:*:*:*:*:*:*

History

05 Mar 2026, 20:09

Type Values Removed Values Added
First Time Gnu wget2
CPE cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* cpe:2.3:a:gnu:wget2:*:*:*:*:*:*:*:*

05 Mar 2026, 19:55

Type Values Removed Values Added
CPE cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-69194 - () https://access.redhat.com/security/cve/CVE-2025-69194 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2425773 - () https://bugzilla.redhat.com/show_bug.cgi?id=2425773 - Issue Tracking, Third Party Advisory
First Time Gnu wget
Gnu

09 Jan 2026, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 08:15

Updated : 2026-03-05 20:09


NVD link : CVE-2025-69194

Mitre link : CVE-2025-69194

CVE.ORG link : CVE-2025-69194


JSON object : View

Products Affected
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')