CVE-2025-67718

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Dec 2025, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 01:16

Updated : 2025-12-12 15:18


NVD link : CVE-2025-67718

Mitre link : CVE-2025-67718

CVE.ORG link : CVE-2025-67718


JSON object : View

Products Affected

No product.

CWE
CWE-178

Improper Handling of Case Sensitivity

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor