Skip to content

Formidable <3.2.4 Arbitrary File Upload Critical Severity #1799

Closed
@domcorso-nib

Description

@domcorso-nib

When running npm audit report we are seeing a critical vulnerability due to the version of formidable being used.

I've seen previous issues such as #1725 which indicate that it has been revoked but I can see it on the GitHub database last updated a few hours ago:
GHSA-8cp3-66vr-3r4c

Are there any plans to upgrade to the latest version of formidable?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions