An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
https://www.youtube.com/watch?v=i3xJR-91rrM
https://www.npmjs.com/package/connect-multiparty
https://github.com/expressjs/connect-multiparty/releases/tag/2.2.0