Authentication Flaw in HeyForm Open-Source Form Builder
CVE-2026-63429
8.6HIGH
What is CVE-2026-63429?
The HeyForm open-source form builder is vulnerable due to a lack of authentication checks on the POST /api/upload endpoint, which is accessible to any anonymous user. This oversight allows harmful users to upload various file types, including documents and media, without restrictions. The absence of context validation means requests are processed indiscriminately, leading to public exposure of uploaded files on the HeyForm domain. To mitigate this risk, the vulnerability was patched in version 3.0.0-rc.9.
Affected Version(s)
heyform < 3.0.0-rc.9
