File Upload Vulnerability in Formidable by Node Formidable
CVE-2025-46653
3.1LOW
Summary
Formidable, a file upload middleware for Node.js, contains a vulnerability in versions 2.1.0 through 3.x prior to 3.5.3, which relates to its dependence on hexoid for filename obscurity. Although hexoid is used to prevent the guessing of filenames for untrusted executable content, it lacks cryptographic security. This could potentially allow an attacker to guess parts of the filename under certain conditions, although typical use cases may limit the risk of successful exploitation. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
Formidable 2.1.0 < 3.5.3
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved