Intel

AIKIDO-2026-10766

verbb/formie is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 8, 2026

30

Low Risk

This Affects:

PHPverbb/formie
1.3.3 - 3.1.19
Fixed in 3.1.20
Are you affected? Scan for Free

TL;DR

Affected versions of this package may disclose valid GraphQL schema details through verbose Did you mean error hints, allowing unauthenticated users to infer field names, argument names, and expected values even when production settings are intended to suppress such guidance. An attacker could exploit this by sending crafted invalid GraphQL queries and analyzing the returned suggestions to enumerate the schema, refine follow-up queries, and map internal API structure for further targeted abuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

verbb/formie is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.3.3 - 3.1.19.

How to fix this

Upgrade the verbb/formie library to the patch version.