Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12478 | Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content |
Github GHSA |
GHSA-75v8-2h7p-7m2m | Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content |
Thu, 16 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:node-formidable:formidable:*:*:*:*:*:node.js:*:* |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | formidable: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Formidable | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 26 Apr 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content. | |
| Weaknesses | CWE-338 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-29T15:22:37.440Z
Reserved: 2025-04-26T00:00:00.000Z
Link: CVE-2025-46653
Updated: 2025-04-29T14:53:54.144Z
Status : Analyzed
Published: 2025-04-26T21:15:14.403
Modified: 2026-05-13T14:15:37.517
Link: CVE-2025-46653
OpenCVE Enrichment
Updated: 2025-07-12T23:06:12Z
EUVD
Github GHSA