Description
All versions of socket.io-fileare vulnerable to a file restriction bypass. The validation for valid file types only happens on the client-side, which allows an attacker to intercept the Websocket request post-validation and alter the name value to upload any file types.
No fix is currently available.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.31
References
Could your website be exposed too?
SmartScanner can check your website for File restriction bypass in socket.io-file and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Path Traversal in socket.io-file - CVE-2020-15779
- Validation bypass in jpv - CVE-2020-17479
- ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse` - CVE-2020-28462
- LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read - CVE-2026-39859


