๐Ÿ” CVE Alert

CVE-2026-63429

HIGH 8.6

HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX, XLS/XLSX, CSV, TXT, MP4, images, etc., up to 10 MB) and receive a permanent public URL on the HeyForm domain. The endpoint is used by both authenticated form creators and unauthenticated form submitters; because no form-context binding exists, every request to it is anonymously accepted. Version 3.0.0-rc.9 contains a patch for the issue.

CWE CWE-306 CWE-434
Vendor heyform
Product heyform
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for heyform heyform

Be the first to know when new high vulnerabilities affecting heyform heyform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low

Affected Versions

heyform / heyform
< 3.0.0-rc.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/heyform/heyform/security/advisories/GHSA-432x-54v2-p7p7 github.com: https://github.com/heyform/heyform/commit/092e255e9e02565de1b3c057f3dad849160952d2