CVE-2025-69194: Wget2: arbitrary file write via metalink path traversal in gnu wget2

Published Dec 29, 2025
·
Updated

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.

Other sources

Path traversal vulnerability in the Metalink processing logic of GNU Wget2. The issue arises when wget2 trusts attacker-supplied <file name> values in Metalink v3/v4 documents without proper sanitization. By specifying traversal sequences or absolute paths, an attacker can cause wget2 to create, truncate, or overwrite arbitrary files writable by the victim user. The vulnerability is remotely exploitable, requires no authentication, and can lead to data loss or potential code execution by overwriting user-executed configuration or startup files.

Red Hat

Affected Software

2 affected components
GNU Wget2
GNU Wget2<2.2.1

Event History

Dec 29, 2025
Data Sourced
via Red Hat·02:15 PM
DescriptionSeverityAffected Software
Jan 9, 2026
CVE Published
via MITRE·07:53 AM
Data Sourced
via MITRE·07:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-69194?

CVE-2025-69194 is classified as a moderate severity vulnerability.

2

How do I fix CVE-2025-69194?

To fix CVE-2025-69194, update GNU Wget2 to the latest patched version where the vulnerability is addressed.

3

What type of vulnerability is CVE-2025-69194?

CVE-2025-69194 is a path traversal vulnerability occurring in the handling of Metalink documents.

4

What systems are affected by CVE-2025-69194?

CVE-2025-69194 affects GNU Wget2 installations that process Metalink documents.

5

Can CVE-2025-69194 lead to data loss?

Yes, CVE-2025-69194 can potentially allow attackers to write files to unintended locations, which may result in data loss.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203