Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2025-7783: form-data library may let attackers tamper with data
CVE-2025-7783 · published 4 days ago
Summary
The form-data code used by ljharb/form-data, rootio/@rootio/form-data, and similar packages had a security weakness that could let a malicious user interfere with how data is handled. This could affect any application that relies on these libraries to manage file uploads or form submissions. Apply the latest updates provided by Root to fix the problem and keep your software safe.
What to do
- Update ljharb form-data to version 2.5.4.
- Update ljharb form-data to version 3.0.4.
- Update ljharb form-data to version 4.0.4.
- Update rootio @rootio/form-data to version 2.3.3-root.io.3.
- Update ljharb form-data to version 4.0.4-aikido.1.
- Update rootio @rootio/form-data to version 4.0.4-root.io.1.
- Update ljharb form-data to version 3.0.4-aikido.1.
- Update rootio @rootio/form-data to version 3.0.4-root.io.1.
- Update ljharb form-data to version 2.3.3-aikido.3.
- Update form-data to version 3.0.4-aikido.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | ljharb | form-data |
< 2.5.4 >= 3.0.0, < 3.0.4 >= 4.0.0, < 4.0.4 Fix: upgrade to 2.5.4
|
| Root:npm | rootio | @rootio/form-data |
< 2.3.3-root.io.3 < 4.0.4-root.io.1 < 3.0.4-root.io.1 Fix: upgrade to 2.3.3-root.io.3
|
| Root:npm | ljharb | form-data |
< 4.0.4-aikido.1 < 3.0.4-aikido.1 < 2.3.3-aikido.3 Fix: upgrade to 4.0.4-aikido.1
|
| Root:npm | – | form-data |
< 3.0.4-aikido.1 Fix: upgrade to 3.0.4-aikido.1
|
Original advisory text
CVE-2025-7783 in form-data - Patched by Root
Root has patched CVE-2025-7783 in the form-data package for Root:npm. Multiple fixed versions available.
References
- https://github.com/benweissmann/CVE-2025-7783-poc
- https://github.com/advisories/GHSA-fjxv-7rqg-78g4
- https://lists.debian.org/debian-lts-announce/2025/07/msg00023.html
- https://npmjs.com/form-data URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7783.j... Vendor Advisory
- https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4
- https://nvd.nist.gov/vuln/detail/CVE-2025-7783 Vendor Advisory
- https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d...
- https://github.com/form-data/form-data Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-330Use of Insufficiently Random Values
Timeline
Published28 Sep 2026
Updated30 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta