CVE-2026-45697
CRITICAL9.8EPSS 0.10%Formie: Pre-authenticated server-side template injection in Hidden fields
描述
### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
受影響套件(1)
- Packagist/verbb/formie>= 3.0.0-beta.1, < 3.1.24
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(5)
- PATCHhttps://github.com/verbb/formie
- WEBhttps://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3
- WEBhttps://github.com/verbb/formie/releases/tag/2.2.20
- WEBhttps://github.com/verbb/formie/releases/tag/3.1.24
- WEBhttps://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2