Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-2087.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "2.11.0" } ] } ]