GHSA-rm8p-cx58-hcvx: Axios has Transitive Critical Vulnerability via form-data — Predictable Boundary Values (CVE-2025-7783)
A critical vulnerability exists in the form-data package used by axios@1.10.0
. The issue allows an attacker to predict multipart boundary values generated using Math.random()
, opening the door to HTTP parameter pollution or injection attacks.
This was submitted in issue #6969 and addressed in pull request #6970.
References
Code Behaviors & Features
Detect and mitigate GHSA-rm8p-cx58-hcvx with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →