Vulnerabilities/

File restriction bypass in socket.io-file

Severity:
High

Description

All versions of socket.io-fileare vulnerable to a file restriction bypass. The validation for valid file types only happens on the client-side, which allows an attacker to intercept the Websocket request post-validation and alter the name value to upload any file types.

No fix is currently available.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
socket.io-file
Anything's wrong? Let us know Last updated on January 22, 2026