verbb/formie is vulnerable to Generation of Error Message Containing Sensitive Information
30
Low Risk
Affected versions of this package may disclose valid GraphQL schema details through verbose Did you mean error hints, allowing unauthenticated users to infer field names, argument names, and expected values even when production settings are intended to suppress such guidance. An attacker could exploit this by sending crafted invalid GraphQL queries and analyzing the returned suggestions to enumerate the schema, refine follow-up queries, and map internal API structure for further targeted abuse.
You are affected if you are using a version that falls within the vulnerable range.
verbb/formie is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.3.3 - 3.1.19.
Upgrade the verbb/formie library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant