chore(deps): update dependency form-data to v4.0.6 [security] - #9973
Conversation
🦋 Changeset detectedLatest commit: 2592a1f The changes in this PR will be included in the next version bump. This PR includes changesets to release 9 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
2bbcdcd to
0f64149
Compare
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
5556709 to
4a65004
Compare
b8db22d to
f7a1eef
Compare
d76636c to
f21f872
Compare
f21f872 to
7fd8788
Compare
d7ecc91 to
6611846
Compare
There was a problem hiding this comment.
Code review found no issues
No high-confidence issues detected in this change.
Still open from earlier reviews (1):
- Unresolved: 1 minor or pre-existing.
This review covers commit 596c25b, which is no longer the latest commit on this pull request; later commits are not covered by it.
There was a problem hiding this comment.
Confirmed fixed: the lockfile now resolves form-data to 4.0.6 for packages/electron-publish (specifier ^4.0.5, resolved version 4.0.6), and no form-data@ 4.0.5 entries remain anywhere in pnpm-lock.yaml — addressing the gap flagged in my earlier inline comment. This is a mechanical, dependency-only fix with no remaining concerns.
Extended reasoning...
Follow-up commit 35166ae updates pnpm-lock.yaml so that packages/electron-publish's form-data dependency (used by bitbucketPublisher.ts and gitlabPublisher.ts) now actually resolves to the patched 4.0.6 line, not just the pnpm-workspace.yaml exclude entry added earlier. This is exactly the gap my prior inline comment identified, and it is now closed. The change remains lockfile/config-only with no application code touched.
defer
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
There was a problem hiding this comment.
Looks good — the earlier concern (form-data still pinned to 4.0.5 in package.json/lockfile) has since been fixed by commit 2592a1f: packages/electron-publish/package.json now specifies form-data ^4.0.6 and pnpm-lock.yaml resolves it to 4.0.6, matching the changeset and the minimumReleaseAgeExclude entry.
Extended reasoning...
My prior inline finding was that the security-update PR only added the minimumReleaseAgeExclude entry without actually bumping form-data in package.json/pnpm-lock.yaml, leaving the vulnerable 4.0.5 resolved for electron-publish. A later commit (2592a1f, by mmaietta, not the PR author's own bot resolution) addresses this directly: package.json now specifies form-data ^4.0.6 and the lockfile resolves it to 4.0.6. No other outstanding objections exist in the timeline, and the remaining diff (changeset, workspace exclude, lockfile) is mechanical and consistent.
This PR contains the following updates:
4.0.5→4.0.6form-data: CRLF injection in form-data via unescaped multipart field names and filenames
CVE-2026-12143 / GHSA-hmw2-7cc7-3qxx
More information
Details
Summary
form-databuildsmultipart/form-datarequest bodies. Through v4.0.5, thefieldname passed toFormData#appendand thefilenameoption are concatenated directly into theContent-Dispositionheader with no escaping of CR (\r), LF (\n), or". An application that uses untrusted input as a field name or filename therefore lets an attacker terminate the header line and either inject additional headers or smuggle whole additional multipart parts into the request the application forwards to a backend.This is CWE-93 (CRLF injection). It is a divergence from how browsers and the WHATWG HTML spec serialize form-data (they escape these characters), so the fix is to match that behavior. Severity is conditional: it depends on the consuming application passing attacker-controlled data as a field name or filename. Applications that only use fixed/trusted field names are not affected.
Details
In
lib/form_data.js,_multiPartHeaderbuilds the part header as:and
_getContentDispositionbuildsfilename="' + filename + '"'. Neither escapes control characters, so a\r\ninfield/filenameends the header line. The same applies to", which can break out of the quoted parameter.Proof of concept
Before the fix this emits an injected
X-Injected: trueheader line. A field name that also includes--<boundary>sequences can introduce additional parts (e.g. an extraname="is_admin"field), which a downstream parser accepts as legitimate.Impact
For an application that uses untrusted field names/filenames:
is_admin,role) — the primary demonstrated impact.Claims of guaranteed privilege escalation, authentication bypass, high confidentiality impact, and availability impact are application-dependent downstream consequences, not properties of
form-dataitself, and are not demonstrated by the PoC.Severity
The demonstrated, library-attributable impact is integrity (field/header injection); there is no demonstrated confidentiality disclosure or availability impact in
form-dataitself, and exploitation requires the consuming app to feed untrusted data into field names/filenames. A Moderate (≈5.3,I:L) rating is also defensible given that precondition.Patch
Fixed in 4.0.6, 3.0.5, and 2.5.6. Users on older 0.x/1.x/2.x releases should upgrade to 2.5.6 or later.
The fix escapes
\r,\n, and"as%0D,%0A, and%22in field names and filenames, matching the WHATWG HTMLmultipart/form-dataencoding algorithm that browsers implement. This neutralizes the injection while leaving ordinary field names (includingname[0], dotted, and unicode names) unchanged.Workaround
Until upgrading, validate or reject field names/filenames that contain control characters before calling
append:Credit
Reported by yueyueL.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
form-data/form-data (form-data)
v4.0.6Compare Source
Commits
"in field names and filenames8dff42c@ljharb/eslint-config,auto-changelog,tapef31d21ehasown,mime-types92ae0ebjs-randomness-predictor67b0f65Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.