Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP Content-Type header. This allows a remote attacker (or a Man-in-the-Middle, if the comic is served over HTTP) to write arbitrary files outside the target directory (if additional conditions are met). This issue is fixed in version 3.2.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4vcx-3pj3-44m7 | Dosage vulnerable to a Directory Traversal through crafted HTTP responses |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Nov 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP Content-Type header. This allows a remote attacker (or a Man-in-the-Middle, if the comic is served over HTTP) to write arbitrary files outside the target directory (if additional conditions are met). This issue is fixed in version 3.2. | |
| Title | Dosage vulnerable to Directory Traversal through crafted HTTP responses | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-07T03:02:41.838Z
Reserved: 2025-10-28T21:07:16.440Z
Link: CVE-2025-64184
No data.
Status : Received
Published: 2025-11-07T04:15:46.947
Modified: 2025-11-07T04:15:46.947
Link: CVE-2025-64184
No data.
OpenCVE Enrichment
No data.
Github GHSA