The form-data dep has a critical security issue with version <4.0.4. Looks like yarn lock indicates only 4.0.3 is used here CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-7783