Executive brief
Dosage, a tool used to download and archive webcomics, is vulnerable to a security flaw where malicious comic websites can inject harmful scripts into the files Dosage generates. If a user scrapes a compromised or malicious comic and then opens the resulting HTML or RSS summary file in their web browser, the attacker's code could run automatically. This could allow an attacker to steal information from the user's browser or perform unauthorized actions on the user's behalf.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Dosage <= 3.2 within `dosagelib/events.py`. The `HtmlEventHandler` and `RSSEventHandler` classes write user-controlled data, specifically comic descriptions and page URLs extracted via XPath, directly into output files without HTML escaping. While the scraper component unescapes HTML entities during extraction, the output handlers fail to re-escape them before file generation. An attacker can exploit this by hosting a malicious webcomic containing JavaScript in metadata fields (like image titles). When a victim scrapes this comic and opens the generated HTML or RSS file in a browser, the script executes. The vulnerability is mitigated in version 3.3 by implementing proper HTML escaping.
Affected products
- webcomics dosage <= 3.2
Timeline
- 2026-05-24: disclosed: Initial disclosure on GitHub Advisories
- 2026-06-26: advisory: Advisory published/updated
- 2026-06-26: patched: Fixed in version 3.3