CVE-2022-36082

    Dashboard / Vulnerabilities / CVE-2022-36082

    CVE-2022-36082

    Published: 7 Sept 2022Last Modified: 12 Aug 2026

    Summary: mangadex-downloader vulnerable to unauthorized file reading

    Details: mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<location>` is a web URL location (http, https), mangadex-downloader between versions 1.3.0 and 1.7.2 will try to open and read a file in local disk for each line of website contents. Version 1.7.2 contains a patch for this issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 439b5644bca306e326198c4e356ad5493766344e

    Affected versions

    v1.7.1
    v1.7.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-36082 | CVE-DB