PT-2026-43087 · Dazeb · Markdown-Downloader

Kkkkko

·

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2026-9472

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download markdown/list downloaded files/create subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-9472

Affected Products

Markdown-Downloader