<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agnuwget/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 23 Sep 2026 13:59:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agnuwget/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Code Execution Vulnerability in GNU Wget</title><link>https://feed.craftedsignal.io/briefs/2026-09-wget-rce/</link><pubDate>Wed, 23 Sep 2026 13:59:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wget-rce/</guid><description>A local vulnerability in GNU Wget, identified as CVE-2024-38428, allows an attacker to achieve arbitrary code execution through the processing of malformed input strings.</description><content:encoded><![CDATA[<p>GNU Wget contains a security vulnerability that permits a local attacker to execute arbitrary code. The flaw is triggered by improper handling of specific input strings during the file retrieval process. By tricking a local user into executing a crafted command involving a malicious URL or file path, an attacker can cause the application to process inputs in a way that leads to unauthorized code execution. Depending on the privileges of the user executing the command, this may facilitate privilege escalation within the affected system. This impact is significant for environments where users rely on Wget for automated task scripting or frequent command-line file downloads.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local attacker to gain the same execution context as the user running the Wget utility. In scenarios where Wget is executed by privileged users or automated system services, this vulnerability can lead to full system compromise or persistence, significantly impacting the integrity and security of the affected workstation or server.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of all instances of GNU Wget to the version containing the fix for CVE-2024-38428. Monitor system logs for unusual command-line arguments passed to wget, particularly those involving long or encoded strings that may indicate attempts to exploit buffer overflows or parsing logic errors.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>