Description
Summary: A flaw in path handling could allow an attacker to access protected API endpoints by sending a crafted request path. This issue could result in unauthorized data disclosure under certain configurations.
Recommendation
Update the formio package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0-rc.1, < 4.4.3 < 3.5.7** Patched version(s): **4.4.3 3.5.7**
References
Could your website be exposed too?
SmartScanner can check your website for Formio improperly authorized permission elevation through specially crafted request path and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cube Core is vulnerable to privilege escalation via a specially crafted request - CVE-2026-25958
- TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update - CVE-2025-60542
- nanotar is vulnerable to path traversal in parseTar() and parseTarGzip() - CVE-2025-69874
- Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity - CVE-2025-58451


