CVE-2025-54371: Withdrawn Advisory: Axios has Transitive Critical Vulnerability via form-data
(updated )
- Vulnerability Type: Predictable Value / HTTP Parameter Pollution
- Risk: Critical (CVSS 9.4)
- Impacted Users: Any application using axios@1.10.0 to submit multipart form-data
This could potentially allow attackers to:
- Interfere with multipart request parsing
- Inject unintended parameters
- Exploit backend deserialization logic depending on content boundaries
References
- github.com/advisories/GHSA-fjxv-7rqg-78g4
- github.com/advisories/GHSA-rm8p-cx58-hcvx
- github.com/axios/axios
- github.com/axios/axios/issues/6969
- github.com/axios/axios/pull/6970
- github.com/axios/axios/security/advisories/GHSA-rm8p-cx58-hcvx
- nvd.nist.gov/vuln/detail/CVE-2025-54371
- nvd.nist.gov/vuln/detail/CVE-2025-7783
- security.snyk.io/vuln/SNYK-JS-FORMDATA-10841150
Code Behaviors & Features
Detect and mitigate CVE-2025-54371 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →