High severity7.5NVD Advisory· Published Jul 15, 2020· Updated Jun 17, 2026
CVE-2020-15779
CVE-2020-15779
Description
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
socket.io-filenpm | <= 2.0.31 | — |
Affected products
3- cpe:2.3:a:socket.io-file_project:socket.io-file:*:*:*:*:*:node.js:*:*Range: <=2.0.31
Patches
Vulnerability mechanics
References
4- www.npmjs.com/advisories/1519nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-9h4g-27m8-qjrgnvdThird Party AdvisoryADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-15779ghsaADVISORY
- www.npmjs.com/package/socket.io-filenvdProductThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.