CVE-2025-69194: wget2: Arbitrary File Write via Metalink Path Traversal in GNU Wget2

Severity: Critical

CVSS Score: 9.8

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.