Skip to content

CVE-2025-7783 #300

Description

@Speedy1991

Hey, I just saw this package is using a really outdated version of superagent which has a peer dependency to form-data with a CVE 9.x

https://github.com/Asana/node-asana/blob/master/package.json#L20

$ yarn why form-data
└─ superagent@npm:5.3.1
   └─ form-data@npm:3.0.2 (via npm:^3.0.0)

https://nvd.nist.gov/vuln/detail/CVE-2025-7783

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions