Security Vulnerability in GNU Wget2 Affects File Handling
CVE-2025-69194

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
9 January 2026

What is CVE-2025-69194?

A security issue has been identified in GNU Wget2, particularly in how it processes Metalink documents. The application does not adequately validate the file paths specified in the Metalink elements. This oversight allows attackers to manipulate the application to write files to unexpected locations within the system, potentially leading to data loss and further compromises of the user's environment. It is vital for users of GNU Wget2 to ensure they are using the latest version and apply any relevant security patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Arkadi Vainbrand for reporting this issue.
.