CVE-2026-103648
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
- Published Oct 2, 2026
- CVSS 9.1 critical
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available