Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP Content-Type header. This allows a remote attacker (or a Man-in-the-Middle, if the comic is served over HTTP) to write arbitrary files outside the target directory (if additional conditions are met). This issue is fixed in version 3.2.
History

Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Webcomics
Webcomics dosage
Vendors & Products Webcomics
Webcomics dosage

Fri, 07 Nov 2025 03:30:00 +0000

Type Values Removed Values Added
Description Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP Content-Type header. This allows a remote attacker (or a Man-in-the-Middle, if the comic is served over HTTP) to write arbitrary files outside the target directory (if additional conditions are met). This issue is fixed in version 3.2.
Title Dosage vulnerable to Directory Traversal through crafted HTTP responses
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-07T03:02:41.838Z

Updated: 2025-11-07T03:02:41.838Z

Reserved: 2025-10-28T21:07:16.440Z

Link: CVE-2025-64184

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-07T04:15:46.947

Modified: 2025-11-07T04:15:46.947

Link: CVE-2025-64184

cve-icon Redhat

No data.