OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103648

CRITICAL · CVSS 9.1 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical path traversal vulnerability in image-downloader version 4.3.0 allows attackers to manipulate download URLs, enabling them to write response data outside the designated directory. This could lead to unauthorized file access or overwriting of sensitive files on the server. Organizations using this version of image-downloader should prioritize immediate remediation to mitigate potential exploitation risks.

CVE
CVE-2026-103648
Severity
CRITICAL
CVSS
9.1
EPSS
0.41%

Original NVD Description

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.