Intel

AIKIDO-2026-240740

verbb/formie is vulnerable to Missing Authorization

Missing AuthorizationGHSA-q6g7-g2wg-h43h Published Yesterday

54

Medium Risk

This Affects:

PHPverbb/formie
0.0.1 - 3.1.43
Fixed in 3.1.44
Are you affected? Scan for Free

TL;DR

Formie's FieldsController::actionGetElementSelectOptions action builds a field's select options by instantiating a class named in the request, without an authorization check or a restriction on which class name is accepted. An unauthorized or unauthenticated request can reach this action and supply an arbitrary class name, so classes the action was never meant to expose get instantiated. The fix adds an authorization check to the action and limits which classes it will instantiate.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

verbb/formie is vulnerable to Missing Authorization in versions 0.0.1 - 3.1.43.

How to fix this

Upgrade the verbb/formie library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform