VDB
Sign up
HIGH7.8

GHSA-6495-8jvh-f28x

File restriction bypass in socket.io-file

Details

All versions of `socket.io-file`are vulnerable to a file restriction bypass. The validation for valid file types only happens on the client-side, which allows an attacker to intercept the Websocket request post-validation and alter the `name` value to upload any file types.

No fix is currently available. Consider using an alternative package until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/socket.io-file
Introduced in: 0

No fixed version published yet for socket.io-file (npm). Pin to a known-safe version or switch to an alternative.

References