Vulnerabilities/

Path Traversal in socket.io-file

Severity:
High

Description

All versions of socket.io-file are vulnerable to Path Traversal. The package fails to sanitize user input and uses it to generate the file upload paths. The socket.io-file::createFile message contains a name option that is passed directly to path.join().

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
socket.io-file
Anything's wrong? Let us know Last updated on January 09, 2023