VYPR
Medium severity5.5NVD Advisory· Published Mar 14, 2025· Updated Jun 17, 2026

CVE-2024-29409

CVE-2024-29409

Description

File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@nestjs/commonnpm
>= 11.0.0-next.1, < 11.0.1611.0.16
@nestjs/commonnpm
< 10.4.1610.4.16

Affected products

3
  • Nestjs/Nest2 versions
    cpe:2.3:a:nestjs:nest:10.3.2:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:nestjs:nest:10.3.2:*:*:*:*:node.js:*:*
    • (no CPE)
  • ghsa-coords
    Range: >= 11.0.0-next.1, < 11.0.16

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.