CVE-2026-9472
dazeb markdown-downloader index.ts create_subdirectory path traversal
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
13th
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-22 |
| Vendor | dazeb |
| Product | markdown-downloader |
| Published | May 25, 2026 |
| Last Updated | May 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for dazeb markdown-downloader
Be the first to know when new medium vulnerabilities affecting dazeb markdown-downloader are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
dazeb / markdown-downloader
3d4394b34b6c99d81af817623af55e3384df5a6a
References
Credits
๐ KkKkKO (VulDB User) VulDB CNA Team