Skip to main content
HIGH

CVE-2023-27534

CVSS v3

8.8

HIGH

EPSS Score

2.2 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

Technical details

Published
2023-03-30

Frequently asked questions

What is CVE-2023-27534?

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

Is CVE-2023-27534 actively exploited?

Active exploitation of CVE-2023-27534 has not been confirmed. Its EPSS score was 2.2% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-27534?

CVE-2023-27534 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2023-27534 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key