CVE-2025-46653
CVSS 3.1 Score 3.1 of 10 (low)
Details
Summary
CVE-2025-46653 affects Formidable (node-formidable) versions 2.1.0 through 3.x before 3.5.3. This vulnerability stems from the reliance on hexoid to secure filenames for untrusted executable content. Hexoid, however, is documented as not cryptographically secure, leaving the system vulnerable to potential attacks where only the last two characters of a hexoid string need to be guessed. It is important to note that this does not necessarily mean attackers can upload and execute their own content, but the lack of cryptographic security in hexoid usage is a concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.