CVE-2025-54371: High severity npm/axios vulnerability

Published Jul 23, 2025
·
Updated

Withdrawn Advisory This advisory has been withdrawn because users of Axios 1.10.0 have the flexibility to use a patched version of form-data, the software in which the vulnerability originates, without upgrading Axios to address GHSA-fjxv-7rqg-78g4.

Original Description A critical vulnerability exists in the form-data package used by axios@1.10.0. The issue allows an attacker to predict multipart boundary values generated using Math.random(), opening the door to HTTP parameter pollution or injection attacks.

This was submitted in issue #6969 and addressed in pull request #6970.

Details The vulnerable package form-data@4.0.0 is used by axios@1.10.0 as a transitive dependency. It uses non-secure, deterministic randomness (Math.random()) to generate multipart boundary strings.

This flaw is tracked under Snyk Advisory SNYK-JS-FORMDATA-10841150 and CVE-2025-7783.

Affected form-data versions: - <2.5.4 - >=3.0.0 <3.0.4 - >=4.0.0 <4.0.4

Since axios@1.10.0 pulls in form-data@4.0.0, it is exposed to this issue.

PoC 1. Install Axios: - npm install axios@1.10.0 2.Run snyk test: Tested 104 dependencies for known issues, found 1 issue, 1 vulnerable path.

✗ Predictable Value Range from Previous Values [Critical Severity] in form-data@4.0.0 via axios@1.10.0 > form-data@4.0.0

3. Trigger a multipart/form-data request. Observe the boundary header uses predictable random values, which could be exploited in a targeted environment.

Impact

- Vulnerability Type: Predictable Value / HTTP Parameter Pollution - Risk: Critical (CVSS 9.4) - Impacted Users: Any application using axios@1.10.0 to submit multipart form-data

This could potentially allow attackers to: - Interfere with multipart request parsing - Inject unintended parameters - Exploit backend deserialization logic depending on content boundaries

Related Links GitHub Issue #6969

Pull Request #xxxx (replace with actual link)

Snyk Advisory

form-data on npm

Other sources

Rejected reason: This CVE is a duplicate of another CVE.

NVD

Affected Software

1 affected componentFixes available
npm/axios=1.10.0
1.11.0

Event History

Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jul 23, 2025
Advisory Published
via GitHub·04:49 PM
Data Sourced
via GitHub·04:49 PM
DescriptionSeverityAffected Software
Rejected
via MITRE·08:34 PM
Rejected
via MITRE·08:42 PM
CVE Published
via NVD·09:15 PM
Data Sourced
via NVD·09:15 PM
Description
Jul 24, 2025
Withdrawn
via GitHub·01:35 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-54371?

CVE-2025-54371 is classified as a critical vulnerability due to its potential impact on user security.

2

How do I fix CVE-2025-54371?

To remediate CVE-2025-54371, upgrade Axios to version 1.11.0 or use a secured version of form-data.

3

Which versions of Axios are affected by CVE-2025-54371?

Axios version 1.10.0 is affected by CVE-2025-54371.

4

Is it necessary to upgrade Axios to fix CVE-2025-54371?

Upgrading Axios is one way to fix CVE-2025-54371, but users can also utilize a patched version of form-data.

5

What software does CVE-2025-54371 originate from?

CVE-2025-54371 originates from vulnerabilities within the form-data software used in Axios.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203