Authentication Flaw in HeyForm Open-Source Form Builder
CVE-2026-63429

8.6HIGH

Key Information:

Vendor

Heyform

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63429?

The HeyForm open-source form builder is vulnerable due to a lack of authentication checks on the POST /api/upload endpoint, which is accessible to any anonymous user. This oversight allows harmful users to upload various file types, including documents and media, without restrictions. The absence of context validation means requests are processed indiscriminately, leading to public exposure of uploaded files on the HeyForm domain. To mitigate this risk, the vulnerability was patched in version 3.0.0-rc.9.

Affected Version(s)

heyform < 3.0.0-rc.9

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.