Arbitrary Field Injection Vulnerability in HeyForm Open-Source Form Builder
CVE-2026-63428

5.8MEDIUM

Key Information:

Vendor

Heyform

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63428?

HeyForm, an open-source form builder, is susceptible to an arbitrary field injection vulnerability. Before version 3.0.0-rc.9, the completeSubmission function accepts a hiddenFields array without validating its contents against the schema defined for the form's hidden fields. This lack of validation allows an attacker to submit arbitrary key/value pairs, including potentially malicious XSS payloads and unauthorized metadata, which are then stored verbatim in the submission data. These unregulated fields are subsequently sent unchanged to all webhook integrations tied to the form, posing a significant risk to the integrity and security of the systems interfacing with the form submissions. The issue has been rectified in HeyForm version 3.0.0-rc.9.

Affected Version(s)

heyform < 3.0.0-rc.9

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.