PT-2025-45115 · Dosage · Dosage
Published
2025-11-04
·
Updated
2025-11-12
·
CVE-2025-64184
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dosage versions 3.1 and below
Description
Dosage is a comic strip downloader and archiver. When downloading comic images, the software constructs target file names from various sources, including the page URL, image URL, and page content. The basename is stripped of directory-traversing characters, but the file extension is derived from the HTTP Content-Type header. This allows a remote attacker, or a Man-in-the-Middle if the comic is served over HTTP, to potentially write arbitrary files outside the intended target directory under certain conditions.
Recommendations
Update to version 3.2.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dosage