Description
All versions of socket.io-fileare vulnerable to a file restriction bypass. The validation for valid file types only happens on the client-side, which allows an attacker to intercept the Websocket request post-validation and alter the name value to upload any file types.
No fix is currently available.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.31
References
Related Issues
- Path Traversal in socket.io-file - CVE-2020-15779
- Validation bypass in jpv - CVE-2020-17479
- ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse` - CVE-2020-28462
- LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read - CVE-2026-39859
You might also like:
- Tags:
- npm
- socket.io-file
Anything's wrong? Let us know Last updated on January 22, 2026


