CVE-2026-103648: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
image-downloaderto a version that resolves this vulnerability.Fixed in 4.3.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using image-downloader 4.3.0 are exposed when an attacker can control the URL supplied for a download. The attacker does not need privileges or user interaction according to the reported vector.
What can an attacker do?
An attacker-controlled download URL can cause downloaded response data to be written outside the configured destination directory. The reported impact includes integrity and availability effects.
Is a default configuration known to be affected?
The available information does not state whether the default configuration is affected. Exposure depends on whether untrusted input can control the download URL.
How can I determine whether my application is affected?
Check whether the application uses npm/image-downloader version 4.3.0 and whether any untrusted party can influence the URL passed to its download functionality. Also review whether downloaded files could be written with permissions that affect application or system availability.