High severity7.8NVD Advisory· Published Oct 6, 2020· Updated Jun 17, 2026
CVE-2020-24807
CVE-2020-24807
Description
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
socket.io-filenpm | <= 2.0.31 | — |
Affected products
3- cpe:2.3:a:socket.io-file_project:socket.io-file:*:*:*:*:*:node.js:*:*Range: <=2.0.31
- socket.io-file/socket.io-filedescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-6495-8jvh-f28xnvdThird Party AdvisoryADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-24807ghsaADVISORY
- www.npmjs.com/advisories/1564nvdThird Party AdvisoryWEB
- www.npmjs.com/package/socket.io-filenvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.