Path Traversal Vulnerability in Image-Downloader by Demsking
CVE-2026-103648

9.1CRITICAL

Key Information:

Vendor

Demsking

Vendor
CVE Published:
2 October 2026

What is CVE-2026-103648?

The Image-Downloader version 4.3.0 contains a path traversal vulnerability that allows an attacker with control over the download URL to manipulate the application into writing downloaded response data outside of the designated directory. This could lead to unauthorized access to sensitive files within the server or filesystem, potentially compromising the integrity and confidentiality of the affected system. Users of this version are advised to take immediate action to mitigate risk.

Affected Version(s)

image-downloader 0 < 4.3.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amirhossein Roustaei (@eternullsec), Eternull Security
.