Junglewise Threat Intelligence

CVE-2026-82291: HeyForm CORS misconfiguration with credential handling

CVE-2026-82291 · Severity: high · CVSS 8.1 · Published 2026-08-28

Technologies: HeyForm. Vendors: HeyForm.

Executive brief

HeyForm is an open-source form builder used to create and manage web forms. The application incorrectly reflects user-supplied Origin headers in CORS responses while allowing credentials, enabling attackers to make authenticated requests from malicious websites. A logged-in user visiting a compromised page could have their form submissions, workspace data, projects, and account settings accessed or modified without authorization.

Technical details

The vulnerability is a CORS misconfiguration where the application uses `origin: true` in the CORS policy combined with `credentials: true`, which causes the server to echo back the Origin header from any request and allow authentication cookies to be sent cross-origin. This violates the same-origin policy and enables cross-site request forgery (CSRF) attacks via authenticated GraphQL queries. An attacker can craft a malicious webpage that, when visited by an authenticated HeyForm user, executes arbitrary GraphQL queries with the victim's authentication context, accessing or modifying workspaces, projects, forms, submissions, and respondent data. The fix requires restricting the CORS origin to specific trusted domains rather than accepting all origins. The vulnerability affects HeyForm versions before 3.0.0-rc.8.

Affected products

  • HeyForm HeyForm before 3.0.0-rc.8

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Fixed in version 3.0.0-rc.8

References

Related threats