Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0004

NIXPKGS-2026-0004
published on 11 Jan 2026
updated 1 week, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed maintainer @SuperSandro2000
  • @LeSuisse accepted as draft
  • @LeSuisse published on GitHub
Wget2: arbitrary file write via metalink path traversal in gnu wget2

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.

Affected products

wget2
  • =<2.2.0
  • ==2.2.1

Matching in nixpkgs