Loading HuntDB...

GHSA-4j25-c9rf-fp5f

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

Related CVEs

Key Information

GHSA ID
GHSA-4j25-c9rf-fp5f
Published
March 30, 2023 9:30 PM
Last Modified
March 17, 2024 12:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 19, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.