CVE-2025-54371: High severity npm/axios vulnerability
Withdrawn Advisory This advisory has been withdrawn because users of Axios 1.10.0 have the flexibility to use a patched version of form-data, the software in which the vulnerability originates, without upgrading Axios to address GHSA-fjxv-7rqg-78g4.
Original Description A critical vulnerability exists in the form-data package used by axios@1.10.0. The issue allows an attacker to predict multipart boundary values generated using Math.random(), opening the door to HTTP parameter pollution or injection attacks.
This was submitted in issue #6969 and addressed in pull request #6970.
Details The vulnerable package form-data@4.0.0 is used by axios@1.10.0 as a transitive dependency. It uses non-secure, deterministic randomness (Math.random()) to generate multipart boundary strings.
This flaw is tracked under Snyk Advisory SNYK-JS-FORMDATA-10841150 and CVE-2025-7783.
Affected form-data versions: - <2.5.4 - >=3.0.0 <3.0.4 - >=4.0.0 <4.0.4
Since axios@1.10.0 pulls in form-data@4.0.0, it is exposed to this issue.
PoC 1. Install Axios: - npm install axios@1.10.0 2.Run snyk test: Tested 104 dependencies for known issues, found 1 issue, 1 vulnerable path.
✗ Predictable Value Range from Previous Values [Critical Severity] in form-data@4.0.0 via axios@1.10.0 > form-data@4.0.0
3. Trigger a multipart/form-data request. Observe the boundary header uses predictable random values, which could be exploited in a targeted environment.
Impact
- Vulnerability Type: Predictable Value / HTTP Parameter Pollution - Risk: Critical (CVSS 9.4) - Impacted Users: Any application using axios@1.10.0 to submit multipart form-data
This could potentially allow attackers to: - Interfere with multipart request parsing - Inject unintended parameters - Exploit backend deserialization logic depending on content boundaries
Related Links GitHub Issue #6969
Pull Request #xxxx (replace with actual link)
Snyk Advisory
form-data on npm
Other sources
Rejected reason: This CVE is a duplicate of another CVE.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54371?
CVE-2025-54371 is classified as a critical vulnerability due to its potential impact on user security.
How do I fix CVE-2025-54371?
To remediate CVE-2025-54371, upgrade Axios to version 1.11.0 or use a secured version of form-data.
Which versions of Axios are affected by CVE-2025-54371?
Axios version 1.10.0 is affected by CVE-2025-54371.
Is it necessary to upgrade Axios to fix CVE-2025-54371?
Upgrading Axios is one way to fix CVE-2025-54371, but users can also utilize a patched version of form-data.
What software does CVE-2025-54371 originate from?
CVE-2025-54371 originates from vulnerabilities within the form-data software used in Axios.