CVE-2020-24807 describes a critical vulnerability in the Node.js socket.io-file package (through version 2.0.31) where client-side file type validation can be bypassed. This allows remote attackers to upload executable files by manipulating the JSON name field, leading to arbitrary code execution. With a CVSS score of 7.8 (HIGH), this vulnerability requires user interaction (UI:R) but has a low attack complexity (AC:L) and can result in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). While a Reddit post suggests in-the-wild exploitation, there are no known public exploits in Metasploit or ExploitDB, and the vulnerability affects an unsupported product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.31CPE matchmatch criteria | cpe:2.3:a:socket.io-file_project:socket.io-file:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.