PatchSiren

dazeb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW dazeb CVE published 2026-05-25

CVE-2026-9472

A path traversal vulnerability exists in the dazeb markdown-downloader project, affecting functions in src/index.ts including download_markdown, list_downloaded_files, and create_subdirectory. The vulnerability allows remote attackers to manipulate file paths, potentially leading to unauthorized file access or modification outside intended directories. The project does not use formal versioning, making af [truncated]