CVE-2026-103648
CriticalPublished
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader
- Published
- Oct 2, 2026
- Updated
- Oct 3, 2026
- Assigning CNA
- GitLab
- Evidence observed
- Oct 3, 2026
Primary CVSS
9.1/ 10Critical
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HSummary
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
Sources
Advisory and PoC for CVE-2026-103648, a path traversal (CWE-22) in image-downloader 4.3.0 enabling arbitrary file write, with root-cause analysis, patch diff, and Docker lab.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.