PatchSiren

demsking CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL demsking CVE published 2026-10-02

CVE-2026-103648

A critical vulnerability in image-downloader 4.3.0 allows attackers to write downloaded response data outside the configured destination directory via path traversal. This vulnerability has significant implications for data integrity and requires immediate attention from defenders. The vulnerability is triggered when an attacker can control the download URL, allowing them to manipulate the file path and w [truncated]