GHSA-x7m9-mwc2-g6w2
Formie: Pre-authenticated server-side template injection in Hidden fields
Quick fix
GHSA-x7m9-mwc2-g6w2 — verbb/formie: upgrade to the fixed version with the command below.
composer require verbb/formie:^3.1.24Details
### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain.
### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24)
### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.0-beta.1Fixed in: 3.1.24composer require verbb/formie:^3.1.24References
- https://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45697[ADVISORY]
- https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3[WEB]
- https://github.com/verbb/formie[PACKAGE]
- https://github.com/verbb/formie/releases/tag/2.2.20[WEB]
- https://github.com/verbb/formie/releases/tag/3.1.24[WEB]