Vulnerability DatabaseGHSA-6495-8jvh-f28x

GHSA-6495-8jvh-f28x
JavaScript vulnerability analysis and mitigation

Overview

The socket.io-file package through version 2.0.31 for Node.js contains a critical file restriction bypass vulnerability (CVE-2020-24807, GHSA-6495-8jvh-f28x). This security flaw was discovered and disclosed on October 2, 2020, affecting all versions of the package up to and including version 2.0.31. The vulnerability is particularly concerning as it impacts a package that is no longer maintained by its developers (GitHub Advisory).

Technical details

The vulnerability stems from an improper input validation (CWE-20) where the package relies solely on client-side validation for file types. The severity of this vulnerability is rated as High with a CVSS v3.1 base score of 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The technical assessment indicates that while the attack vector is local and requires user interaction, it needs no privileges to execute and can result in high impacts across confidentiality, integrity, and availability (NVD).

Impact

The vulnerability can lead to arbitrary code execution on affected systems. When successfully exploited, it allows attackers to bypass file type restrictions and potentially upload malicious executable files, compromising the security of the application. The high CVSS scores for confidentiality, integrity, and availability (all rated as High) indicate severe potential consequences if exploited (GitHub Advisory).

Exploitability

The vulnerability can be exploited by intercepting the WebSocket request post-validation and modifying the name value to upload any file type. The attack complexity is rated as Low, requiring no special privileges, though it does need user interaction. The local attack vector suggests that the attacker needs some form of local access to execute the exploit (GitHub Advisory).

Mitigation and workarounds

No official fix is currently available for this vulnerability as the package is no longer maintained. The recommended mitigation strategy is to switch to an alternative package that provides similar functionality with proper security measures (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56677HIGH8.6
  • JavaScript logoJavaScript
  • 9router
NoNoAug 17, 2026
CVE-2026-73410HIGH8.5
  • JavaScript logoJavaScript
  • @budibase/server
NoNoAug 17, 2026
CVE-2026-64657HIGH8.4
  • JavaScript logoJavaScript
  • budibase
NoYesAug 17, 2026
CVE-2026-69148HIGH7.1
  • JavaScript logoJavaScript
  • mlflow
NoYesAug 17, 2026
CVE-2026-69146MEDIUM6.5
  • JavaScript logoJavaScript
  • mlflow
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management