{"id":"GHSA-rm8p-cx58-hcvx","summary":"Withdrawn Advisory: Axios has Transitive Critical Vulnerability via form-data","details":"### Withdrawn Advisory\nThis advisory has been withdrawn because users of Axios 1.10.0 have the flexibility to use a patched version of form-data, the software in which the vulnerability originates, without upgrading Axios to address GHSA-fjxv-7rqg-78g4.\n\n### Original Description\nA critical vulnerability exists in the form-data package used by `axios@1.10.0`. The issue allows an attacker to predict multipart boundary values generated using `Math.random()`, opening the door to HTTP parameter pollution or injection attacks.\n\nThis was submitted in [issue #6969](https://github.com/axios/axios/issues/6969) and addressed in [pull request #6970](https://github.com/axios/axios/pull/6970).\n\n### Details\nThe vulnerable package `form-data@4.0.0` is used by `axios@1.10.0` as a transitive dependency. It uses non-secure, deterministic randomness (`Math.random()`) to generate multipart boundary strings.\n\nThis flaw is tracked under [Snyk Advisory SNYK-JS-FORMDATA-10841150](https://security.snyk.io/vuln/SNYK-JS-FORMDATA-10841150) and [CVE-2025-7783](https://security.snyk.io/vuln/SNYK-JS-FORMDATA-10841150).\n\nAffected `form-data` versions:\n- \u003c2.5.4\n- \u003e=3.0.0 \u003c3.0.4\n- \u003e=4.0.0 \u003c4.0.4\n\nSince `axios@1.10.0` pulls in `form-data@4.0.0`, it is exposed to this issue.\n\n\n### PoC\n1. Install Axios: - `npm install axios@1.10.0`\n2.Run `snyk test`:\n```\nTested 104 dependencies for known issues, found 1 issue, 1 vulnerable path.\n\n✗ Predictable Value Range from Previous Values [Critical Severity]\nin form-data@4.0.0 via axios@1.10.0 \u003e form-data@4.0.0\n\n```\n3. Trigger a multipart/form-data request. Observe the boundary header uses predictable random values, which could be exploited in a targeted environment.\n\n\n### Impact\n\n- **Vulnerability Type**: Predictable Value / HTTP Parameter Pollution\n- **Risk**: Critical (CVSS 9.4)\n- **Impacted Users**: Any application using axios@1.10.0 to submit multipart form-data\n\n\nThis could potentially allow attackers to:\n- Interfere with multipart request parsing\n- Inject unintended parameters\n- Exploit backend deserialization logic depending on content boundaries\n\n### Related Links\n[GitHub Issue #6969](https://github.com/axios/axios/issues/6969)\n\n[Pull Request #xxxx](https://github.com/axios/axios/pull/xxxx) (replace with actual link)\n\n[Snyk Advisory](https://security.snyk.io/vuln/SNYK-JS-FORMDATA-10841150)\n\n[form-data on npm](https://www.npmjs.com/package/form-data)","aliases":["CVE-2025-54371"],"modified":"2026-09-10T03:50:26.315092435Z","published":"2025-07-23T16:49:38Z","withdrawn":"2025-07-24T13:35:30Z","database_specific":{"github_reviewed_at":"2025-07-23T16:49:38Z","nvd_published_at":"2025-07-23T21:15:26Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/axios/axios/security/advisories/GHSA-rm8p-cx58-hcvx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54371"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7783"},{"type":"WEB","url":"https://github.com/axios/axios/issues/6969"},{"type":"WEB","url":"https://github.com/axios/axios/pull/6970"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fjxv-7rqg-78g4"},{"type":"PACKAGE","url":"https://github.com/axios/axios"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-FORMDATA-10841150"}],"affected":[{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.10.0"},{"fixed":"1.11.0"}]}],"versions":["1.10.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-rm8p-cx58-hcvx/GHSA-rm8p-cx58-hcvx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}