Intel

AIKIDO-2025-10436

multer is vulnerable to Uncaught Exception

Uncaught ExceptionCVE-2025-48997 Published Jul 7, 2025

87

High Risk

This Affects:

JSmulter
1.4.4-lts.1 - 2.0.0
Fixed in 2.0.2
Are you affected? Scan for Free

TL;DR

Multer, a Node.js middleware for handling multipart/form-data, contains a vulnerability in versions 1.4.4-lts.1 up to 2.0.0. An attacker can exploit this flaw to trigger a Denial of Service (DoS) by submitting a file upload request with an empty string as a field name. This results in an unhandled exception, causing the process to crash.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

multer is vulnerable to Uncaught Exception in versions 1.4.4-lts.1 - 2.0.0.

How to fix this

Upgrade the Multer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform