NONE · 0

CVE-2025-67718

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access p...

Vulnerability Description

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-67718?

CVE-2025-67718 is a documented vulnerability. Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access p...

How severe is CVE-2025-67718?

CVSS scoring is not yet available for CVE-2025-67718. Check NVD for updates.

Is there a patch for CVE-2025-67718?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.