← Terug naar overzicht

HeyForm versions before 3.0.0-rc.8 contain a CORS misconfiguration where the server reflects the request Origin header in CORS responses while also allowing credentials. This flaw enables attackers to perform cross-origin authenticated requests from malicious web pages visited by logged-in users. By leveraging this vulnerability, attackers can execute authenticated GraphQL queries to access sensitive data including workspaces, projects, forms, submissions, and respondent information. Additionally, attackers may modify account settings of affected users. The vulnerability requires user interaction, specifically a logged-in user visiting a malicious page. A fix was introduced in version 3.0.0-rc.8 via a commit to the HeyForm repository. The issue has been publicly disclosed through GitHub Security Advisories and VulnCheck.

Affected products

  • HeyForm

Related CVE's

  • CVE-2026-82291

Categories

  • Data Breach & Exfiltration
  • Identity & Access
  • Web Technologies