CRITICAL
demsking
CVE published 2026-10-02
CVE-2026-103648
A critical vulnerability in image-downloader 4.3.0 allows attackers to write downloaded response data outside the configured destination directory via path traversal. This vulnerability has significant implications for data integrity and requires immediate attention from defenders. The vulnerability is triggered when an attacker can control the download URL, allowing them to manipulate the file path and w [truncated]