---
id: CVE-2026-103648
title: >-
  Path traversal in image-downloader 4.3.0 allows an attacker who can control
  the download URL to cause downloaded response data to be written outside the
  configured destination directory.
summary: >-
  Path traversal in image-downloader 4.3.0 allows an attacker who can control
  the download URL to cause downloaded response data to be written outside the
  configured destination directory.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
vendor: demsking
product: image-downloader
affected:
  - image-downloader < 4.3.1
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T16:16:44.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103648'
references:
  - url: >-
      https://gitlab.com/demsking/image-downloader/-/commit/fb4454304276e2439fb19b98836b3ba903b3aaea
    label: cve@gitlab.com
  - url: 'https://gitlab.com/demsking/image-downloader/-/work_items/32'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T16:22:59.526Z'
---

## Overview

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
