GHSA-m654-769v-qjv7
Formio improperly authorized permission elevation through specially crafted request path
Quick fix
GHSA-m654-769v-qjv7 — formio: upgrade to the fixed version with the command below.
npm install formio@3.5.7Details
# Security Advisory: Unauthorized permission elevation through specially crafted request path
**Summary:** A flaw in path handling could allow an attacker to access protected API endpoints by sending a crafted request path. This issue could result in unauthorized data disclosure under certain configurations.
**Impact:** In affected configurations, an unauthenticated or unauthorized request could retrieve data from endpoints that should be protected.
**Affected versions:** <= 3.5.6 <= 4.4.2
**Fixed in:** 3.5.7 4.4.3
**Mitigation / Workarounds:** Upgrade to 3.5.7 or later.
**Disclosure timeline:** Discovered 2025-05-22; fixed 2025-05-30; publicly disclosed 2025-12.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/formio/formio/security/advisories/GHSA-m654-769v-qjv7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-67718[ADVISORY]
- https://github.com/formio/formio/commit/1665b7c99e3cf3246db7ff0b4ff732231dc6903b[WEB]
- https://github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478[WEB]
- https://github.com/formio/formio[PACKAGE]