Skip to content

UID2-7307: fix form-data CVE-2026-12143 (HIGH) — upgrade to >=4.0.6#248

Merged
sophia-chen-ttd merged 1 commit into
mainfrom
syw-UID2-7307-fix-form-data-cve
Jun 16, 2026
Merged

UID2-7307: fix form-data CVE-2026-12143 (HIGH) — upgrade to >=4.0.6#248
sophia-chen-ttd merged 1 commit into
mainfrom
syw-UID2-7307-fix-form-data-cve

Conversation

@sophia-chen-ttd

Copy link
Copy Markdown
Contributor

Summary

Fixes CVE-2026-12143 (HIGH): form-data multipart library vulnerability. Updates the npm override from ^4.0.4 to >=4.0.6 so all transitive consumers resolve to the patched 4.0.6 release.

Test plan

  • CI vulnerability scan passes (Trivy should no longer report CVE-2026-12143)
  • Build and tests pass

…12143 (UID2-7307)

CVE-2026-12143 (HIGH): form-data multipart library vulnerability.
Updates the npm override from ^4.0.4 to >=4.0.6 so all transitive
consumers of form-data resolve to the patched 4.0.6 release.
@sophia-chen-ttd sophia-chen-ttd merged commit 0d2087f into main Jun 16, 2026
3 checks passed
@sophia-chen-ttd sophia-chen-ttd deleted the syw-UID2-7307-fix-form-data-cve branch June 16, 2026 05:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants