VendorsSindresorhusfile-typeany version
Vulnerabilities

Sindresorhus file-type any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-36313
An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.
Published 2022-07-21 · Modified
5.5EPSS 0.004
CVE-2026-32630
file-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry
Published 2026-03-13 · Analyzed
5.3EPSS 0.004
CVE-2026-31808
file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header
Published 2026-03-10 · Analyzed
5.3EPSS 0.004