Vulnerability Management

GNU Wget2 bug allows file overwrites

Adobe Stock

Popular web file downloading command line tool GNU Wget2 has been impacted by a critical flaw, tracked as CVE-2025-69194, which could be harnessed to overwrite files through malicious Metalink downloads, according to Cyber Security News.

Researchers found that Wget2 does not properly check file paths inside Metalink metadata, a format used to list download sources and checksums. By inserting path traversal strings, an attacker can force the tool to save files outside the intended directory. The impact depends on the permissions of the user running wget2. Successful exploitation may overwrite system files, applications, security settings, or libraries, leading to data corruption or local code execution.

Red Hat marked the issue as Important and said user interaction is required to open the malicious Metalink file. There is no complete enterprise-ready mitigation yet. Users should avoid untrusted Metalink files and watch for updates from the GNU Wget2 project while patches are being prepared.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds