Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m654-769v-qjv7 | Formio improperly authorized permission elevation through specially crafted request path |
Thu, 11 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Form
Form form.io |
|
| Vendors & Products |
Form
Form form.io |
Thu, 11 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3. | |
| Title | Formio improperly authorized permission elevation through specially crafted request path | |
| Weaknesses | CWE-178 CWE-200 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-11T15:35:44.111Z
Reserved: 2025-12-10T18:46:14.762Z
Link: CVE-2025-67718
Updated: 2025-12-11T15:35:34.238Z
Status : Deferred
Published: 2025-12-11T01:16:01.157
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-67718
No data.
OpenCVE Enrichment
Updated: 2025-12-11T16:20:06Z
Github GHSA