top of page
perceptive_background_267k.jpg

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. A…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

HeyForm versions before 3.0.0-rc.8 contain a CORS misconfiguration where the server reflects the request Origin header in CORS responses while also allowing credentials. This flaw enables attackers to perform cross-origin authenticated requests from malicious web pages visited by logged-in users. By leveraging this vulnerability, attackers can execute authenticated GraphQL queries to access sensitive data including workspaces, projects, forms, submissions, and respondent information. Additionally, attackers may modify account settings of affected users. The vulnerability requires user interaction, specifically a logged-in user visiting a malicious page. A fix was introduced in version 3.0.0-rc.8 via a commit to the HeyForm repository. The issue has been publicly disclosed through GitHub Security Advisories and VulnCheck.

Technical details

Mitigation steps:

Affected products:

HeyForm

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page