Security Vulnerability: Update form-data Dependency to >= 4.0.4
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 1k
- Forks
- 165
- PR merge metrics
- No merged PRs in 30d
Description
Hello!
I'm raising this issue in relation to the following CVE: CVE-2025-7783, which affects form-data version 4.0.0 — the version currently used by @openid/appauth.
This vulnerability is classified as critical, and it has been addressed in form-data version 4.0.4. To ensure the security of applications depending on AppAuth-JS, it is important to update the form-data dependency to version 4.0.4 or later.
Thanks for your work on this project!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the package manifest and lockfile that declare form-data, then inspect how the current 4.0.0 dependency is recorded. Update it to version 4.0.4 or later, refresh any lockfile entry, and run the existing test suite to confirm AppAuth-JS still passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js, typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100