High severity7.5OSV Advisory· Published Jul 30, 2020· Updated Jun 17, 2026
CVE-2020-7699
CVE-2020-7699
Description
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
express-fileuploadnpm | < 1.1.9 | 1.1.9 |
Affected products
2- Range: 0.4.0, 1.1.1-alpha.2, 1.1.6, …
Patches
Vulnerability mechanics
References
8- github.com/richardgirges/express-fileupload/issues/236nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-EXPRESSFILEUPLOAD-595969nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-9wcg-jrwf-8gg7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7699ghsaADVISORY
- security.netapp.com/advisory/ntap-20200821-0003/nvdThird Party Advisory
- github.com/richardgirges/express-fileupload/commit/db495357d7557ceb5c034de91a7a574bd12f9b9fghsaWEB
- github.com/richardgirges/express-fileupload/pull/237ghsaWEB
- security.netapp.com/advisory/ntap-20200821-0003ghsaWEB
News mentions
0No linked articles in our index yet.