verbb/formie is vulnerable to Path Traversal
75
High Risk
Affected versions of this package are vulnerable to path traversal due to insufficient sanitization of user-supplied filenames in file upload handling. Uploaded file names and dynamically generated filename formats may contain path components such as ../, allowing an attacker to manipulate file paths during upload or asset creation. This could result in files being written outside the intended directory or overwriting unintended files. The issue is fixed by sanitizing uploaded filenames and stripping path components before generating or saving asset names.
You are affected if you are using a version that falls within the vulnerable range.
verbb/formie is vulnerable to Path Traversal in versions 0.0.1 - 2.2.11 and 3.0.0 - 3.1.12.
Upgrade the verbb/formie library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant