Sceawere
Vulnerability Detail
CVE-2026-103648UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
image-downloader Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 7h ago
- Vendor
- demsking
- Product
- image-downloader
- Attack Type
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-02T16:16:44.370Z",
"pubdate": "2026-10-02T16:16:44.370Z",
"executiveSummary": "A critical path traversal vulnerability has been identified in the image-downloader library, specifically affecting version 4.3.0. This security flaw enables a remote attacker who can manipulate or control the download URL parameter to execute an arbitrary file write attack. By crafting a malicious URL containing directory traversal sequences (such as '../'), the attacker can bypass the application's intended directory restrictions.\nConsequently, the downloaded response payload can be written to locations outside the configured destination directory on the host filesystem. The risk implications of this vulnerability are severe, as it allows unauthorized file creation or the overwriting of existing configuration, system, or application files, potentially leading to arbitrary code execution, denial of service, or complete system compromise. To exploit this vulnerability, the attacker must have the ability to supply or influence the input URL processed by the library. This vulnerability poses a significant threat to applications utilizing this package for downloading remote resources without strict input validation, highlighting the need for immediate remediation and input sanitization controls.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient validation and sanitization of the target filename resolved during the file download process in image-downloader version 4.3.0. When an application invokes the library to download an image, the destination path is typically constructed by combining a pre-configured output directory with a filename extracted from the provided download URL.\nIn a secure implementation, the application must strip any directory traversal sequences, such as dot-dot-slash ('../') or backslash characters, from the resolved filename to ensure that the write operation is strictly jailed within the destination folder. However, in version 4.3.0 of image-downloader, the library fails to properly sanitize these sequences when processing user-controlled URLs.\nThe attack flow unfolds as follows: First, an attacker identifies an input vector where the target application accepts a user-provided URL to download and save an image via the image-downloader library. Second, the attacker crafts a malicious URL containing directory traversal sequences within the path component (for example, 'http://malicious-source.com/../../../var/www/shell.php'). Third, upon receiving the input, the application passes the URL to image-downloader, and the library performs an HTTP request to fetch the remote payload from the specified URL.\nOnce the response data is received, the library determines the output file path by extracting the filename from the URL path string without filtering out the traversal characters. The library then concatenates the configured base destination directory path with the unsanitized filename. When the host operating system's filesystem API processes the write operation, the traversal sequences resolve relative to the base directory, causing the file pointer to escape the boundaries of the configured destination folder. Consequently, the downloaded response data is written to an unauthorized directory on the system.\nThis behavioral flaw requires no privileges or authentication on the part of the attacker beyond the ability to submit the download URL. The impact of successful exploitation is highly dependent on the permissions of the process running the application. If the process runs with elevated privileges, the attacker could overwrite critical system files or inject executable scripts into directories mapped by web servers, leading to remote code execution (RCE)."
}