CVE-2024-27480: Malicious File Upload
Published Dec 29, 2025
·Updated
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
Affected Software
2 affected components
npm/vvvebjs
Vvveb Vvvebjs=1.7.2
Event History
Dec 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27480?
CVE-2024-27480 is classified as a high severity vulnerability due to its potential for allowing insecure file uploads.
2
How do I fix CVE-2024-27480?
To fix CVE-2024-27480, upgrade VvvebJs to the latest version where the insecure file upload issue has been addressed.
3
What are the potential impacts of CVE-2024-27480?
The potential impacts of CVE-2024-27480 include unauthorized file upload leading to remote code execution or data breaches.
4
Which versions of VvvebJs are affected by CVE-2024-27480?
CVE-2024-27480 affects VvvebJs version 1.7.2 specifically.
5
Is there a workaround for CVE-2024-27480?
A possible workaround for CVE-2024-27480 involves implementing strict file type validations and restricting upload permissions.