MEDIUM
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header
Published Mar 14, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.34%
Description
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-26416 Advisory
- https://gist.github.com/aydinnyunus/801342361584d1491c67a820a714f53f ExploitMitigationThird Party Advisory
- https://github.com/advisories/GHSA-cj7v-w2c7-cp7c Advisory
- https://github.com/nestjs/nest/blob/83a48b2c7396985144b7a6cd5d3bee1abb7c5d81/packages/common/pipes/file/file-type.validator.ts#L19
- https://github.com/nestjs/nest/issues/13311#issuecomment-1993839495 ExploitIssue Tracking
- https://github.com/nestjs/nest/issues/14876
- https://github.com/nestjs/nest/issues/14876#issuecomment-2796888038
- https://github.com/nestjs/nest/pull/14881
- https://github.com/nestjs/nest/releases/tag/v10.4.16
- https://github.com/nestjs/nest/releases/tag/v11.0.16
- https://nvd.nist.gov/vuln/detail/CVE-2024-29409
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 14, 2025
Updated Mar 17, 2025
Reserved Mar 19, 2024
Link CVE-2024-29409
CISA Vulnrichment
Updated Mar 17, 2025
ENISA EUVD
EUVD-2024-26416 GHSA-CJ7V-W2C7-CP7C Assigner mitre
Published Mar 14, 2025
Updated Mar 17, 2025
Exploited since n/a
Link EUVD-2024-26416