Description
Due to improper type validation in the socket.io-parser library (which is used by the socket.io and socket.io-client packages to encode and decode Socket.IO packets), it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
Recommendation
Update the socket.io-parser package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.4.0, < 3.4.2 < 3.3.3 >= 4.0.0, < 4.0.5 >= 4.1.0, < 4.2.1** Patched version(s): **3.4.2 3.3.3 4.0.5 4.2.1**
References
Could your website be exposed too?
SmartScanner can check your website for Insufficient validation when decoding a Socket.IO packet - socket.io-parser and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Insufficient validation when decoding a Socket.IO packet - CVE-2023-32695
- matrix-js-sdk has insufficient validation when considering a room to be upgraded by another - CVE-2025-59160
- Resource exhaustion in socket.io-parser - CVE-2020-36049
- ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse` - CVE-2020-28462


