Executive brief
dazeb markdown-downloader is a tool used to convert and save web pages as markdown files for use in AI development environments. A security flaw allows a remote user to manipulate file paths, potentially enabling them to read, write, or list files outside of the designated download folder. This could lead to the exposure of sensitive system files or the unauthorized modification of data on the host server.
Technical details
A path traversal vulnerability exists in the download_markdown, list_downloaded_files, and create_subdirectory functions within src/index.ts. The application uses path.join() to combine a user-provided subdirectory name with a base download directory without performing root-boundary validation or sanitizing '../' sequences. An attacker can exploit this by providing crafted path segments to reach arbitrary locations on the filesystem. This enables unauthorized file writes via fs.writeFile, directory listing via fs.readdir, and directory creation via fs.ensureDir. As of the advisory date, the maintainer has not yet released a patch.
Affected products
- dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a
Timeline
- 2026-04-27: disclosed: Issue reported on GitHub repository
- 2026-05-25: advisory: CVE published by VulDB/NVD