Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3.
CVSS
No CVSS.
References
Configurations
No configuration.
History
11 Dec 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-11 01:16
Updated : 2025-12-12 15:18
NVD link : CVE-2025-67718
Mitre link : CVE-2025-67718
CVE.ORG link : CVE-2025-67718
JSON object : View
Products Affected
No product.
