Skip to content

fix: bump form-data to ^4.0.6 (CRLF injection fix) - #584

Merged
c0state merged 3 commits into
4Catalyzer:masterfrom
ajaiswal-qsi-strand:fix/bump-form-data
Sep 3, 2026
Merged

fix: bump form-data to ^4.0.6 (CRLF injection fix)#584
c0state merged 3 commits into
4Catalyzer:masterfrom
ajaiswal-qsi-strand:fix/bump-form-data

Conversation

@ajaiswal-qsi-strand

Copy link
Copy Markdown
Contributor

--Bumps form-data from ^4.0.5 to ^4.0.6 to address CRLF injection vulnerability via unescaped multipart field names and filenames (CVE in form-data < 4.0.6).

@c0state
c0state enabled auto-merge September 3, 2026 16:06
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@c0state
c0state merged commit 87df0b8 into 4Catalyzer:master Sep 3, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants