CVE-2025-7783
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.
- Fix
- Available
- CVSS 4.0
- 9.4 CRITICAL
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-330
- NVD status
- Deferred
- Published
- 2025-07-18
- Attack patterns
- CAPEC-460
CVE-2025-7783 at NVD
1 known exploit for CVE-2025-7783
Proof-of-concept code and exploit modules indexed by Sploitus