{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agnuwget/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2024-38428"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["wget (CVE-2024-38428)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GNU"],"content_html":"\u003cp\u003eGNU Wget contains a security vulnerability that permits a local attacker to execute arbitrary code. The flaw is triggered by improper handling of specific input strings during the file retrieval process. By tricking a local user into executing a crafted command involving a malicious URL or file path, an attacker can cause the application to process inputs in a way that leads to unauthorized code execution. Depending on the privileges of the user executing the command, this may facilitate privilege escalation within the affected system. This impact is significant for environments where users rely on Wget for automated task scripting or frequent command-line file downloads.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to gain the same execution context as the user running the Wget utility. In scenarios where Wget is executed by privileged users or automated system services, this vulnerability can lead to full system compromise or persistence, significantly impacting the integrity and security of the affected workstation or server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all instances of GNU Wget to the version containing the fix for CVE-2024-38428. Monitor system logs for unusual command-line arguments passed to wget, particularly those involving long or encoded strings that may indicate attempts to exploit buffer overflows or parsing logic errors.\u003c/p\u003e\n","date_modified":"2026-09-23T13:59:58Z","date_published":"2026-09-23T13:59:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wget-rce/","summary":"A local vulnerability in GNU Wget, identified as CVE-2024-38428, allows an attacker to achieve arbitrary code execution through the processing of malformed input strings.","title":"Arbitrary Code Execution Vulnerability in GNU Wget","url":"https://feed.craftedsignal.io/briefs/2026-09-wget-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}