Directory Traversal Vulnerability in Dosage Comic Strip Downloader by Webcomics
CVE-2025-64184
8.8HIGH
What is CVE-2025-64184?
A directory traversal vulnerability exists in the Dosage comic strip downloader versions 3.1 and below that allows attackers to exploit file naming constructs. This serious flaw arises when downloading comic images, as the application improperly handles file extensions derived from the HTTP Content-Type header. Consequently, a remote attacker or a Man-in-the-Middle (MitM) could potentially write arbitrary files outside the designated target directory if specific conditions are met. Users are advised to upgrade to version 3.2 to secure their installations and prevent potential attacks.
Affected Version(s)
dosage < 3.2
