# Node red installation high severity CVE (Multer)

**URL:** <https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892>\
**Category:** General\
**Created:** [14 June 2022 05:40 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892 "2022-06-14T05:40:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuvaraj](https://avatars.discourse-cdn.com/v4/letter/y/9de053/32.png) [@yuvaraj](https://discourse.nodered.org/u/yuvaraj)\
**Post date:** [14 June 2022 05:40 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892/1 "2022-06-14T05:40:21Z")

</div>

![Capture](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/b/8b995a3fcd766c20bcc39b724b48913898a2bb52.jpeg)  
i am facing this issue, how do i resolve it.

npm WARN deprecated multer@1.4.4: Multer 1.x is affected by CVE-2022-24434. This is fixed in v1.4.4-lts.1 which drops support for versions of Node.js before 6. Please upgrade to at least Node.js 6 and version 1.4.4-lts.1 of Multer. If you need support for older versions of Node.js, we are open to accepting patches that would fix the CVE on the main 1.x release line, whilst maintaining compatibility with Node.js 0.10.

npm WARN deprecated axios@0.27.0: Formdata complete broken, incorrect build size

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [14 June 2022 09:43 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892/2 "2022-06-14T09:43:52Z")

</div>

I'm afraid there is not much you can do other than raise an issue against Node-RED in GitHub. It requires an update to Node-RED. Of course, depending on what creates those dependencies, if they are deeply embedded, it might not even be possible to update them.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [15 June 2022 06:53 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892/3 "2022-06-15T06:53:23Z")

</div>

It looks like this cve is only a few days old. We are coming up to doing a 2.2.3 maintenance release in the next few days that will pick this up.

A reminder this warning doesn't mean the install failed. It is just a warning.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [15 June 2022 08:21 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892/4 "2022-06-15T08:21:20Z")

</div>

though they seem to have used -beta tags so will need to be specified manually rather than let usual semantic versioning pick it up.

---

<div class="post-metadata">

**Author:** ![wilkillson117](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/wilkillson117/32/63524_2.png) [@wilkillson117](https://discourse.nodered.org/u/wilkillson117)\
**Post date:** [20 June 2022 16:21 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892/5 "2022-06-20T16:21:02Z")

</div>

you can try update Multer with this command:  
npm i multer@1.4.4-lts.1

make sure you are in the correct installation folder of Node-RED, sometimes it is not in C:  
so you won't use:  
C:\>node-red  
only:  
node-red

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [19 August 2022 16:21 UTC](https://discourse.nodered.org/t/node-red-installation-high-severity-cve-multer/63892/6 "2022-08-19T16:21:44Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
