Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. formio
  4. ›
  5. CVE-2025-67718

CVE-2025-67718: Formio improperly authorized permission elevation through specially crafted request path

December 10, 2025 (updated December 11, 2025)

Security Advisory: Unauthorized permission elevation through specially crafted request path

Summary: A flaw in path handling could allow an attacker to access protected API endpoints by sending a crafted request path. This issue could result in unauthorized data disclosure under certain configurations.

Impact: In affected configurations, an unauthenticated or unauthorized request could retrieve data from endpoints that should be protected.

Affected versions: <= 3.5.6 <= 4.4.2

Fixed in: 3.5.7 4.4.3

Mitigation / Workarounds: Upgrade to 3.5.7 or later.

Disclosure timeline: Discovered 2025-05-22; fixed 2025-05-30; publicly disclosed 2025-12.

References

  • github.com/advisories/GHSA-m654-769v-qjv7
  • github.com/formio/formio
  • github.com/formio/formio/commit/1665b7c99e3cf3246db7ff0b4ff732231dc6903b
  • github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478
  • github.com/formio/formio/security/advisories/GHSA-m654-769v-qjv7
  • nvd.nist.gov/vuln/detail/CVE-2025-67718

Code Behaviors & Features

Detect and mitigate CVE-2025-67718 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.5.7, all versions starting from 4.0.0-rc.1 before 4.4.3

Fixed versions

  • 3.5.7
  • 4.4.3

Solution

Upgrade to versions 3.5.7, 4.4.3 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-178: Improper Handling of Case Sensitivity

Source file

npm/formio/CVE-2025-67718.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:20:39 +0000.