Skip to content

Security Vulnerability: Update form-data Dependency to >= 4.0.4 #231

@ThibaRu

Description

@ThibaRu

Hello!

I'm raising this issue in relation to the following CVE: CVE-2025-7783, which affects form-data version 4.0.0 — the version currently used by @openid/appauth.

This vulnerability is classified as critical, and it has been addressed in form-data version 4.0.4. To ensure the security of applications depending on AppAuth-JS, it is important to update the form-data dependency to version 4.0.4 or later.

Thanks for your work on this project!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions