Hacker News new | ask | show | jobs
Socket.io zero-day exploited in the wild (CVE-2020-24807) (lab.wallarm.com)
2 points by stepan_ 2085 days ago
1 comments

Vulnerability is in socket.io-file. Package is downloaded about 500 times a week. The more popular socket.io is not dependant.