
Cloud Vulnerability DB
A community-led vulnerabilities database
The socket.io-file package through version 2.0.31 for Node.js contains a critical file restriction bypass vulnerability (CVE-2020-24807, GHSA-6495-8jvh-f28x). This security flaw was discovered and disclosed on October 2, 2020, affecting all versions of the package up to and including version 2.0.31. The vulnerability is particularly concerning as it impacts a package that is no longer maintained by its developers (GitHub Advisory).
The vulnerability stems from an improper input validation (CWE-20) where the package relies solely on client-side validation for file types. The severity of this vulnerability is rated as High with a CVSS v3.1 base score of 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The technical assessment indicates that while the attack vector is local and requires user interaction, it needs no privileges to execute and can result in high impacts across confidentiality, integrity, and availability (NVD).
The vulnerability can lead to arbitrary code execution on affected systems. When successfully exploited, it allows attackers to bypass file type restrictions and potentially upload malicious executable files, compromising the security of the application. The high CVSS scores for confidentiality, integrity, and availability (all rated as High) indicate severe potential consequences if exploited (GitHub Advisory).
The vulnerability can be exploited by intercepting the WebSocket request post-validation and modifying the name value to upload any file type. The attack complexity is rated as Low, requiring no special privileges, though it does need user interaction. The local attack vector suggests that the attacker needs some form of local access to execute the exploit (GitHub Advisory).
No official fix is currently available for this vulnerability as the package is no longer maintained. The recommended mitigation strategy is to switch to an alternative package that provides similar functionality with proper security measures (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."