Vulnerabilities/

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

Severity:
Low

Description

Formidable (aka node-formidable) 2.x before 2.1.3 and 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not “cryptographically secure.

Recommendation

Update the formidable package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
formidable
Anything's wrong? Let us know Last updated on May 27, 2025