Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Form
Form form.io |
|
| Vendors & Products |
Form
Form form.io |
Thu, 11 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3. | |
| Title | Formio improperly authorized permission elevation through specially crafted request path | |
| Weaknesses | CWE-178 CWE-200 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-11T00:58:43.297Z
Updated: 2025-12-11T15:35:44.111Z
Reserved: 2025-12-10T18:46:14.762Z
Link: CVE-2025-67718
Updated: 2025-12-11T15:35:34.238Z
Status : Awaiting Analysis
Published: 2025-12-11T01:16:01.157
Modified: 2025-12-12T15:18:13.390
Link: CVE-2025-67718
No data.