CyberRota Analysis
AI-GeneratedA critical path traversal vulnerability in image-downloader version 4.3.0 allows attackers to manipulate download URLs, enabling them to write response data outside the designated directory. This could lead to unauthorized file access or overwriting of sensitive files on the server. Organizations using this version of image-downloader should prioritize immediate remediation to mitigate potential exploitation risks.
CVE
CVE-2026-103648
Severity
CRITICAL
CVSS
9.1
EPSS
0.41%
Original NVD Description
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.