A path traversal vulnerability exists in curl <8.0.0SFTPimplementationcausesthetilde(~)charactertobewronglyreplacedwhenusedasaprefixinthefirstpathelement,inadditiontoitsintendeduseasthefirstelementtoindicateapathrelativetotheuser'shomedirectory.Attackerscanexploitthisflawtobypassfilteringorexecutearbitrarycodebycraftingapathlike/~2/foowhileaccessingaserverwithaspecificuser.