Directory Traversal Vulnerability in Dosage Comic Strip Downloader by Webcomics
CVE-2025-64184

8.8HIGH

Key Information:

Vendor

Webcomics

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-64184?

A directory traversal vulnerability exists in the Dosage comic strip downloader versions 3.1 and below that allows attackers to exploit file naming constructs. This serious flaw arises when downloading comic images, as the application improperly handles file extensions derived from the HTTP Content-Type header. Consequently, a remote attacker or a Man-in-the-Middle (MitM) could potentially write arbitrary files outside the designated target directory if specific conditions are met. Users are advised to upgrade to version 3.2 to secure their installations and prevent potential attacks.

Affected Version(s)

dosage < 3.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64184 : Directory Traversal Vulnerability in Dosage Comic Strip Downloader by Webcomics