File Upload Vulnerability in Formidable by Node Formidable
CVE-2025-46653

3.1LOW

Key Information:

Vendor
CVE Published:
26 April 2025

Summary

Formidable, a file upload middleware for Node.js, contains a vulnerability in versions 2.1.0 through 3.x prior to 3.5.3, which relates to its dependence on hexoid for filename obscurity. Although hexoid is used to prevent the guessing of filenames for untrusted executable content, it lacks cryptographic security. This could potentially allow an attacker to guess parts of the filename under certain conditions, although typical use cases may limit the risk of successful exploitation. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

Formidable 2.1.0 < 3.5.3

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-46653 : File Upload Vulnerability in Formidable by Node Formidable | SecurityVulnerability.io