Description
Formidable (aka node-formidable) 2.x before 2.1.3 and 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not “cryptographically secure.
Recommendation
Update the formidable package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.1.0, < 2.1.3 >= 3.1.1-canary.20211030, < 3.5.3** Patched version(s): **2.1.3 3.5.3**
References
Could your website be exposed too?
SmartScanner can check your website for Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Orejime has executable code in HTML attributes - CVE-2025-68457
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - CVE-2025-53892
- MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server - CVE-2025-58444
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18n - CVE-2025-53892


