Server side template injection In verbb/formie
Description
Formie: Pre-authenticated server-side template injection in Hidden fields
Impact
Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior).
Sites with public Formie forms that include at least one Hidden field with that configuration.
No CP login for the reported chain.
Patches
Workarounds
Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible
Otherwise, upgrade to patched versions
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.1.24, 2.2.20 |
Aliases
References