dosage
a comic strip downloader and archiver
Activity
- Latest release
- 3mo ago
- Total releases
- 8
- Cadence
- ~7 months
- Last 12 months
- 2
Details
- License
- MIT
- First release
- Jun 09, 2014
| Version | Released | |
|---|---|---|
3.3
minor
|
3.3
minor
Dependencies (14)
+ 6 more |
|
3.2
minor
1 CVE
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
3.2
minor
Dependencies (14)
+ 6 more |
|
3.1
minor
2 CVEs
CVE-2025-64184
PYSEC-2026-1316
GHSA-4vcx-3pj3-44m7
Jul 07, 2026
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactWhen downloadinging comic images, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP PatchesFixed in release 3.2. The fix is small and self-contained, so distributors might elect to backport the fix to older versions. WorkaroundsNo Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 17 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
Fixed in
3.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
3.1
minor
Dependencies (14)
+ 6 more |
|
3.0
major
2 CVEs
CVE-2025-64184
PYSEC-2026-1316
GHSA-4vcx-3pj3-44m7
Jul 07, 2026
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactWhen downloadinging comic images, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP PatchesFixed in release 3.2. The fix is small and self-contained, so distributors might elect to backport the fix to older versions. WorkaroundsNo Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 17 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
Fixed in
3.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
3.0
major
Dependencies (28)
+ 20 more |
|
2.17
minor
2 CVEs
CVE-2025-64184
PYSEC-2026-1316
GHSA-4vcx-3pj3-44m7
Jul 07, 2026
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactWhen downloadinging comic images, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP PatchesFixed in release 3.2. The fix is small and self-contained, so distributors might elect to backport the fix to older versions. WorkaroundsNo Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 17 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
Fixed in
3.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
2.17
minor
Dependencies (14)
+ 6 more |
|
2.16
minor
2 CVEs
CVE-2025-64184
PYSEC-2026-1316
GHSA-4vcx-3pj3-44m7
Jul 07, 2026
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactWhen downloadinging comic images, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP PatchesFixed in release 3.2. The fix is small and self-contained, so distributors might elect to backport the fix to older versions. WorkaroundsNo Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 17 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
Fixed in
3.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
2.16
minor
Dependencies (14)
+ 6 more |
|
2.15
minor
2 CVEs
CVE-2025-64184
PYSEC-2026-1316
GHSA-4vcx-3pj3-44m7
Jul 07, 2026
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactWhen downloadinging comic images, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP PatchesFixed in release 3.2. The fix is small and self-contained, so distributors might elect to backport the fix to older versions. WorkaroundsNo Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 17 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
Fixed in
3.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
2.15
minor
|
|
2.14
initial
2 CVEs
CVE-2025-64184
PYSEC-2026-1316
GHSA-4vcx-3pj3-44m7
Jul 07, 2026
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ImpactWhen downloadinging comic images, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing characters, the file extension is taken from the HTTP PatchesFixed in release 3.2. The fix is small and self-contained, so distributors might elect to backport the fix to older versions. WorkaroundsNo Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 17 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
Fixed in
3.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-75mw-h36v-2jv7
Jun 26, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryThe HTML and RSS output handlers in CWE: CWE-79 - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) DetailsVulnerable Code LocationsThe vulnerability exists in 1. RSSEventHandler (lines 116-118)
2. HtmlEventHandler (lines 232, 238)
Root Cause
Data Flow
PoCI created a proof-of-concept that demonstrates the vulnerability by simulating a malicious comic source. Prerequisites
PoC FilesCreate these files in a 1.
2.
3.
Running the PoC
PoC Output
The output shows that:
ImpactWho is affected?
Attack scenario
Potential consequences
Recommended FixEscape all user-controlled content before writing to HTML/RSS:
For URLs, validating that they use safe protocols ( Resources
Affected versions
1.10
1.11
1.12
1.13
1.14
1.15
1.7
1.8
1.9
2.0
2.1
2.10
+ 18 more Show less
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.1
3.2
Fixed in
3.3
References Updated Jul 21, 2026 · Source: OSV.dev |
2.14
initial
|