CVE-2026-103648
Received Received - Intake

Path Traversal Vulnerability in image-downloader 4.3.0

Vulnerability report for CVE-2026-103648, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitLab Inc.

Description

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the image-downloader library version 4.3.0. It allows an attacker who controls the download URL to write files outside the intended destination directory. The filename extraction logic fails to restrict the path, enabling crafted URLs to escape the directory and overwrite or create files elsewhere on the filesystem.

Detection Guidance

Check if image-downloader 4.3.0 is installed and review server-side applications using it. Monitor for unexpected file writes outside configured directories. Test with crafted URLs containing path traversal sequences like ../ to see if files are written outside intended locations.

Impact Analysis

If you use image-downloader 4.3.0 in a server-side application where attackers can influence the download URL, they may overwrite critical files outside the intended directory. This could lead to data corruption, denial of service, or unauthorized file creation, depending on filesystem permissions. Remote code execution is not guaranteed but remains a risk.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized file access or modification. For GDPR, it may risk data integrity or unauthorized processing. For HIPAA, it could expose protected health information if files are overwritten or accessed improperly. Organizations must ensure secure file handling to maintain compliance.

Mitigation Strategies

Upgrade image-downloader to a patched version if available. Disable automatic filename extraction from URLs or implement strict path validation. Restrict write permissions on destination directories. Validate all download URLs to prevent path traversal sequences.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103648. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart