High severity7.5NVD Advisory· Published Apr 12, 2022· Updated Jun 17, 2026
CVE-2022-27261
CVE-2022-27261
Description
An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
express-fileuploadnpm | <= 1.3.1 | — |
Affected products
2- Express-FileUpload/Express-FileUploaddescription
Patches
Vulnerability mechanics
References
6- www.youtube.com/watchnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-w4m6-x6c2-j5c9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-27261ghsaADVISORY
- www.npmjs.com/package/express-fileuploadnvdThird Party AdvisoryWEB
- github.com/richardgirges/express-fileupload/issues/312ghsaWEB
- github.com/richardgirges/express-fileupload/issues/316ghsaWEB
News mentions
0No linked articles in our index yet.