openid / openid/AppAuth-JS

Security Vulnerability: Update form-data Dependency to >= 4.0.4

Open
#231 0 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
1k
Forks
165
PR merge metrics
No merged PRs in 30d

Description

Hello!

I'm raising this issue in relation to the following CVE: CVE-2025-7783, which affects form-data version 4.0.0 — the version currently used by @openid/appauth.

This vulnerability is classified as critical, and it has been addressed in form-data version 4.0.4. To ensure the security of applications depending on AppAuth-JS, it is important to update the form-data dependency to version 4.0.4 or later.

Thanks for your work on this project!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the package manifest and lockfile that declare form-data, then inspect how the current 4.0.0 dependency is recorded. Update it to version 4.0.4 or later, refresh any lockfile entry, and run the existing test suite to confirm AppAuth-JS still passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, typescript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.