File Upload Vulnerability in Formidable by Node Formidable
CVE-2025-46653
What is CVE-2025-46653?
Formidable, a file upload middleware for Node.js, contains a vulnerability in versions 2.1.0 through 3.x prior to 3.5.3, which relates to its dependence on hexoid for filename obscurity. Although hexoid is used to prevent the guessing of filenames for untrusted executable content, it lacks cryptographic security. This could potentially allow an attacker to guess parts of the filename under certain conditions, although typical use cases may limit the risk of successful exploitation. Users are advised to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Formidable 2.1.0 < 3.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
