Critical severity9.8NVD Advisory· Published May 16, 2022· Updated Jun 17, 2026
CVE-2022-29353
CVE-2022-29353
Description
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
Affected products
3- cpe:2.3:a:graphql-upload_project:graphql-upload:13.0.0:*:*:*:*:node.js:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =13.0.0
Patches
Vulnerability mechanics
References
1- youtu.be/2kHm_henVM4nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.