File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:LNestjs Nest
APPNestjs10.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2026-40879HIGH7.5same product
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker...
CVE-2026-33011HIGH8.7same product
Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a N...
CVE-2026-2293HIGH8.2same product
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middlewar...
CVE-2026-35515MEDIUM6.3same product
Nest to framework do tworzenia skalowalnych aplikacji serwera Node.js. Przed wersją 11.1.18 metoda SseStream._...
CVE-2025-69211MEDIUM6.9same product
Nest jest frameworkiem do budowania skalowalnych aplikacji Node.js po stronie serwera. Wersje poprzedzające 11...