Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-24807

26
FAUCET Score

CVE-2020-24807 describes a critical vulnerability in the Node.js socket.io-file package (through version 2.0.31) where client-side file type validation can be bypassed. This allows remote attackers to upload executable files by manipulating the JSON name field, leading to arbitrary code execution. With a CVSS score of 7.8 (HIGH), this vulnerability requires user interaction (UI:R) but has a low attack complexity (AC:L) and can result in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). While a Reddit post suggests in-the-wild exploitation, there are no known public exploits in Metasploit or ExploitDB, and the vulnerability affects an unsupported product.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.0.31CPE matchmatch criteria
cpe:2.3:a:socket.io-file_project:socket.io-file:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.10%
Probability of exploitation in next 30 days
EPSS Percentile
79.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0210 is in the 79th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

npmGHSA-6495-8jvh-f28xhigh

File restriction bypass in socket.io-file

Oct 2, 2020

References

github.com / advisories/GHSA-6495-8jvh-f28x
Third Party Advisory
github.com / rico345100/socket.io-file
ProductThird Party Advisory
npmjs.com / advisories/1564
Third Party Advisory
npmjs.com / package/socket.io-file
ProductThird Party Advisory