Junglewise Threat Intelligence

CVE-2025-54371: Axios transitive vulnerability via form-data predictable boundary

CVE-2025-54371 · Severity: low · CVSS 3.1 · Published 2025-07-23

Technologies: Axios. Vendors: Axios, npm.

Executive brief

Axios 1.10.0 indirectly uses a vulnerable version of the form-data library that generates predictable multipart request boundaries using weak randomness. An attacker who can predict these boundaries could inject parameters into file upload requests or interfere with multipart parsing, potentially leading to unauthorized data modification or injection attacks on applications that handle form submissions.

Technical details

The vulnerability exists in the form-data library (versions <2.5.4, 3.0.0–<3.0.4, and 4.0.0–<4.0.4), which uses Math.random() to generate multipart boundary values instead of cryptographically secure randomness. Axios 1.10.0 transitively depends on the vulnerable form-data@4.0.0. An attacker can predict the boundary values used in multipart/form-data requests, enabling HTTP parameter pollution or injection attacks. No authentication or user interaction is required; the attacker needs only network reachability to the application making multipart requests. Exploitation allows interference with multipart request parsing, injection of unintended parameters, or exploitation of backend deserialization logic. The issue is fixed in Axios 1.11.0 (which uses a patched form-data version) and in form-data versions 2.5.4+, 3.0.4+, and 4.0.4+.

Affected products

  • Axios Axios 1.10.0
  • npm form-data <2.5.4, 3.0.0 to <3.0.4, 4.0.0 to <4.0.4

Timeline

  • 2025-07-23: disclosed: Advisory published
  • 2025-07-24: patched: Advisory withdrawn, users can patch form-data independently
  • 2025-07-24: other: Advisory withdrawn because Axios users have flexibility to patch form-data without upgrading Axios

References

Related threats