Junglewise Threat Intelligence

CVE-2022-29623: Connect-Multiparty arbitrary file upload

CVE-2022-29623 · Severity: low · CVSS 3.1 · Published 2022-05-17

Vendors: npm.

Executive brief

Connect-Multiparty is an Express.js middleware that handles file uploads in web applications. An arbitrary file upload vulnerability allows attackers to upload malicious files (such as crafted PDFs) that can lead to code execution on the server, potentially compromising the entire application and sensitive data stored on it.

Technical details

This is an arbitrary file upload vulnerability (CWE-434) in the file upload module of Connect-Multiparty 2.2.0 and earlier versions. The vulnerability allows attackers to bypass file validation controls and upload crafted files, such as PDFs with embedded payloads, which can result in arbitrary code execution on the affected server. The attack vector is local with user interaction required (an authenticated or unauthenticated user must trigger the file upload). Exploitation can lead to complete compromise of confidentiality, integrity, and availability. The repository has been archived as of May 2025, and no official patch is available; users are advised to migrate to alternative solutions or implement strict server-side file validation and sandboxing.

Affected products

  • Express.js Connect-Multiparty 0 through 2.2.0

Timeline

  • 2022-05-17: disclosed: Published in GitHub Advisory Database
  • 2025-05-14: other: Repository archived and no longer actively maintained

References