Skip to content

chore(deps): update dependency form-data to v4.0.6 [security] - #9973

Merged
mmaietta merged 2 commits into
masterfrom
renovate/npm-form-data-vulnerability
Sep 25, 2026
Merged

mmaietta merged 2 commits into
masterfrom
renovate/npm-form-data-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
form-data 4.0.5 → 4.0.6 age confidence

form-data: CRLF injection in form-data via unescaped multipart field names and filenames

CVE-2026-12143 / GHSA-hmw2-7cc7-3qxx

More information

Details

Summary

form-data builds multipart/form-data request bodies. Through v4.0.5, the field name passed to FormData#append and the filename option are concatenated directly into the Content-Disposition header with no escaping of CR (\r), LF (\n), or ". An application that uses untrusted input as a field name or filename therefore lets an attacker terminate the header line and either inject additional headers or smuggle whole additional multipart parts into the request the application forwards to a backend.

This is CWE-93 (CRLF injection). It is a divergence from how browsers and the WHATWG HTML spec serialize form-data (they escape these characters), so the fix is to match that behavior. Severity is conditional: it depends on the consuming application passing attacker-controlled data as a field name or filename. Applications that only use fixed/trusted field names are not affected.

Details

In lib/form_data.js, _multiPartHeader builds the part header as:

'Content-Disposition': ['form-data', 'name="' + field + '"'].concat(contentDisposition || [])

and _getContentDisposition builds filename="' + filename + '"'. Neither escapes control characters, so a \r\n in field/filename ends the header line. The same applies to ", which can break out of the quoted parameter.

Proof of concept
const FormData = require('form-data');
const form = new FormData();
form.append('email"\r\nX-Injected: true\r\nfake="', 'user@example.com');
console.log(form.getBuffer().toString());

Before the fix this emits an injected X-Injected: true header line. A field name that also includes --<boundary> sequences can introduce additional parts (e.g. an extra name="is_admin" field), which a downstream parser accepts as legitimate.

Impact

For an application that uses untrusted field names/filenames:

  • Field injection / override (integrity). Inject or override fields the backend trusts (e.g. is_admin, role) — the primary demonstrated impact.
  • Header injection into the generated multipart part.

Claims of guaranteed privilege escalation, authentication bypass, high confidentiality impact, and availability impact are application-dependent downstream consequences, not properties of form-data itself, and are not demonstrated by the PoC.

Severity

The demonstrated, library-attributable impact is integrity (field/header injection); there is no demonstrated confidentiality disclosure or availability impact in form-data itself, and exploitation requires the consuming app to feed untrusted data into field names/filenames. A Moderate (≈5.3, I:L) rating is also defensible given that precondition.

Patch

Fixed in 4.0.6, 3.0.5, and 2.5.6. Users on older 0.x/1.x/2.x releases should upgrade to 2.5.6 or later.

The fix escapes \r, \n, and " as %0D, %0A, and %22 in field names and filenames, matching the WHATWG HTML multipart/form-data encoding algorithm that browsers implement. This neutralizes the injection while leaving ordinary field names (including name[0], dotted, and unicode names) unchanged.

Workaround

Until upgrading, validate or reject field names/filenames that contain control characters before calling append:

if (/[\r\n]/.test(field)) { throw new Error('invalid field name'); }
Credit

Reported by yueyueL.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

form-data/form-data (form-data)

v4.0.6

Compare Source

Commits
  • [Fix] escape CR, LF, and " in field names and filenames 8dff42c
  • [Dev Deps] update @ljharb/eslint-config, auto-changelog, tape f31d21e
  • [Deps] update hasown, mime-types 92ae0eb
  • [Dev Deps] update js-randomness-predictor 67b0f65

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate label Jun 22, 2026
@changeset-bot

changeset-bot Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2592a1f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 9 packages
Name Type
electron-publish Patch
app-builder-lib Patch
electron-builder Patch
dmg-builder Patch
electron-builder-squirrel-windows Patch
electron-forge-maker-appimage Patch
electron-forge-maker-nsis-web Patch
electron-forge-maker-nsis Patch
electron-forge-maker-snap Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@renovate
renovate Bot force-pushed the renovate/npm-form-data-vulnerability branch 5 times, most recently from 2bbcdcd to 0f64149 Compare June 24, 2026 18:47
@socket-security

socket-security Bot commented Jun 24, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@renovate
renovate Bot force-pushed the renovate/npm-form-data-vulnerability branch 4 times, most recently from 5556709 to 4a65004 Compare June 26, 2026 16:52
@renovate
renovate Bot force-pushed the renovate/npm-form-data-vulnerability branch 7 times, most recently from b8db22d to f7a1eef Compare July 17, 2026 22:18
@renovate
renovate Bot force-pushed the renovate/npm-form-data-vulnerability branch 10 times, most recently from d76636c to f21f872 Compare July 24, 2026 14:17
@renovate
renovate Bot force-pushed the renovate/npm-form-data-vulnerability branch from f21f872 to 7fd8788 Compare July 26, 2026 20:34
@renovate
renovate Bot force-pushed the renovate/npm-form-data-vulnerability branch 13 times, most recently from d7ecc91 to 6611846 Compare September 2, 2026 15:26

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing blocking. The comments below are optional suggestions. There is no need to push a fix for them before merging.

Comment thread pnpm-workspace.yaml

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

Still open from earlier reviews (1):

  • Unresolved: 1 minor or pre-existing.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

Still open from earlier reviews (1):

  • Unresolved: 1 minor or pre-existing.

This review covers commit 596c25b, which is no longer the latest commit on this pull request; later commits are not covered by it.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed fixed: the lockfile now resolves form-data to 4.0.6 for packages/electron-publish (specifier ^4.0.5, resolved version 4.0.6), and no form-data@ 4.0.5 entries remain anywhere in pnpm-lock.yaml — addressing the gap flagged in my earlier inline comment. This is a mechanical, dependency-only fix with no remaining concerns.

Extended reasoning...

Follow-up commit 35166ae updates pnpm-lock.yaml so that packages/electron-publish's form-data dependency (used by bitbucketPublisher.ts and gitlabPublisher.ts) now actually resolves to the patched 4.0.6 line, not just the pnpm-workspace.yaml exclude entry added earlier. This is exactly the gap my prior inline comment identified, and it is now closed. The change remains lockfile/config-only with no application code touched.
defer

@renovate

renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml

<--- Last few GCs --->

[902:0x222c3000]    49179 ms: Scavenge 1461.7 (1488.4) -> 1458.6 (1506.4) MB, pooled: 0 MB, 10.11 / 0.00 ms  (average mu = 0.352, current mu = 0.370) allocation failure; 
[902:0x222c3000]    49936 ms: Mark-Compact (reduce) 1474.2 (1510.2) -> 1464.2 (1484.7) MB, pooled: 0 MB, 68.39 / 0.00 ms  (+ 383.4 ms in 0 steps since start of marking, biggest step 0.0 ms, walltime since start of marking 758 ms) (average mu = 0.474, curr

<--- JS stacktrace --->

FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
----- Native stack trace -----

 1: 0xe36196 node::OOMErrorHandler(char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/22.14.0/bin/node]
 2: 0x123f4a0 v8::Utils::ReportOOMFailure(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/22.14.0/bin/node]
 3: 0x123f777 v8::internal::V8::FatalProcessOutOfMemory(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/22.14.0/bin/node]
 4: 0x146d1a5  [/opt/containerbase/tools/node/22.14.0/bin/node]
 5: 0x146d1d3  [/opt/containerbase/tools/node/22.14.0/bin/node]
 6: 0x148628a  [/opt/containerbase/tools/node/22.14.0/bin/node]
 7: 0x1489458  [/opt/containerbase/tools/node/22.14.0/bin/node]
 8: 0x1cc6071  [/opt/containerbase/tools/node/22.14.0/bin/node]
/usr/local/bin/node: line 18:   902 Aborted                 /opt/containerbase/tools/node/22.14.0/bin/node "$@"

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedform-data@​4.0.5 ⏵ 4.0.699 +1100 +16100 +187100

View full report

@renovate

renovate Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good — the earlier concern (form-data still pinned to 4.0.5 in package.json/lockfile) has since been fixed by commit 2592a1f: packages/electron-publish/package.json now specifies form-data ^4.0.6 and pnpm-lock.yaml resolves it to 4.0.6, matching the changeset and the minimumReleaseAgeExclude entry.

Extended reasoning...

My prior inline finding was that the security-update PR only added the minimumReleaseAgeExclude entry without actually bumping form-data in package.json/pnpm-lock.yaml, leaving the vulnerable 4.0.5 resolved for electron-publish. A later commit (2592a1f, by mmaietta, not the PR author's own bot resolution) addresses this directly: package.json now specifies form-data ^4.0.6 and the lockfile resolves it to 4.0.6. No other outstanding objections exist in the timeline, and the remaining diff (changeset, workspace exclude, lockfile) is mechanical and consistent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant