Executive brief
HeyForm is an open-source tool used to build and manage online forms. A security flaw allows anyone submitting a form to inject unauthorized data into "hidden fields" that are normally controlled by the form creator. This could allow attackers to bypass business logic, spoof administrative roles, or send malicious scripts to third-party services connected via webhooks, potentially compromising downstream systems or internal dashboards.
Technical details
The `completeSubmission` resolver in HeyForm accepts a `hiddenFields` array from the submitter and persists it to the database without validating the provided IDs or names against the form's `form.hiddenFields` schema. Because these fields are stored verbatim and subsequently forwarded to all registered webhook integrations, an anonymous attacker can perform webhook payload poisoning, XSS injection, or override legitimate metadata (such as UTM parameters or authorization roles). The vulnerability stems from improper input validation (CWE-20) and improperly controlled modification of object attributes (CWE-915). The issue is addressed in version 3.0.0-rc.9.
Affected products
- HeyForm HeyForm < 3.0.0-rc.9
Timeline
- 2026-06-25: patched: Fix commit pushed to repository
- 2026-07-01: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: CVE published to NVD