PT-2025-45115 · Dosage · Dosage

Published

2025-11-04

·

Updated

2025-11-12

·

CVE-2025-64184

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dosage versions 3.1 and below
Description Dosage is a comic strip downloader and archiver. When downloading comic images, the software constructs target file names from various sources, including the page URL, image URL, and page content. The basename is stripped of directory-traversing characters, but the file extension is derived from the HTTP Content-Type header. This allows a remote attacker, or a Man-in-the-Middle if the comic is served over HTTP, to potentially write arbitrary files outside the intended target directory under certain conditions.
Recommendations Update to version 3.2.

Exploit

Fix

DoS

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-64184
GHSA-4VCX-3PJ3-44M7

Affected Products

Dosage