CVE-2025-67718: Formio improperly authorized permission elevation through specially crafted request path
(updated )
Security Advisory: Unauthorized permission elevation through specially crafted request path
Summary: A flaw in path handling could allow an attacker to access protected API endpoints by sending a crafted request path. This issue could result in unauthorized data disclosure under certain configurations.
Impact: In affected configurations, an unauthenticated or unauthorized request could retrieve data from endpoints that should be protected.
Affected versions: <= 3.5.6 <= 4.4.2
Fixed in: 3.5.7 4.4.3
Mitigation / Workarounds: Upgrade to 3.5.7 or later.
Disclosure timeline: Discovered 2025-05-22; fixed 2025-05-30; publicly disclosed 2025-12.
References
- github.com/advisories/GHSA-m654-769v-qjv7
- github.com/formio/formio
- github.com/formio/formio/commit/1665b7c99e3cf3246db7ff0b4ff732231dc6903b
- github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478
- github.com/formio/formio/security/advisories/GHSA-m654-769v-qjv7
- nvd.nist.gov/vuln/detail/CVE-2025-67718
Code Behaviors & Features
Detect and mitigate CVE-2025-67718 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →