Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
- Severity:
- Low
Description
Formidable (aka node-formidable) 2.x before 2.1.3 and 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not “cryptographically secure.
Recommendation
Update the formidable package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.1.0, < 2.1.3 >= 3.1.1-canary.20211030, < 3.5.3** Patched version(s): **2.1.3 3.5.3**
References
Related Issues
- Orejime has executable code in HTML attributes - CVE-2025-68457
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - CVE-2025-53892
- MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server - CVE-2025-58444
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18n - CVE-2025-53892
You might also like:
- Tags:
- npm
- formidable
Anything's wrong? Let us know Last updated on May 27, 2025


