{"id":"UBUNTU-CVE-2025-46653","details":"Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not \"cryptographically secure.\" (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.","modified":"2026-09-11T15:00:13.265145146Z","published":"2025-04-26T21:15:00Z","upstream":["CVE-2025-46653"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-46653"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-46653"},{"type":"REPORT","url":"https://github.com/node-formidable/formidable/blob/d0fbec13edc8add54a1afb9ce1a8d3db803f8d47/CHANGELOG.md?plain=1#L10"},{"type":"REPORT","url":"https://github.com/node-formidable/formidable/commit/022c2c5577dfe14d2947f10909d81b03b6070bf5"},{"type":"REPORT","url":"https://github.com/zast-ai/vulnerability-reports/blob/main/formidable/file_upload/report.md"}],"affected":[{"package":{"name":"node-formidable","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.13-1"],"ecosystem_specific":{"binaries":[{"binary_name":"node-formidable","binary_version":"1.0.13-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}},{"package":{"name":"node-formidable","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.13-1"],"ecosystem_specific":{"binaries":[{"binary_name":"node-formidable","binary_version":"1.0.13-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}},{"package":{"name":"node-formidable","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.1-3"],"ecosystem_specific":{"binaries":[{"binary_version":"1.2.1-3","binary_name":"node-formidable"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}},{"package":{"name":"node-formidable","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.1+20200129git8231ea6-1","1.2.1+20200129git8231ea6-2","3.2.1+20220105git2815e91+~cs4.0.6-4"],"ecosystem_specific":{"binaries":[{"binary_version":"3.2.1+20220105git2815e91+~cs4.0.6-4","binary_name":"node-formidable"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}},{"package":{"name":"node-formidable","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.5+20221017git493ec88+~cs4.0.9-1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.2.5+20221017git493ec88+~cs4.0.9-1","binary_name":"node-formidable"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}},{"package":{"name":"node-formidable","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.5+20221017git493ec88+~cs4.0.9-1"],"ecosystem_specific":{"binaries":[{"binary_name":"node-formidable","binary_version":"3.2.5+20221017git493ec88+~cs4.0.9-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}},{"package":{"name":"node-formidable","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/node-formidable?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.5+20221017git493ec88+~cs4.0.9-1"],"ecosystem_specific":{"binaries":[{"binary_name":"node-formidable","binary_version":"3.2.5+20221017git493ec88+~cs4.0.9-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-46653.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}