Intel

AIKIDO-2026-244440

verbb/formie is vulnerable to Missing Authorization

Missing AuthorizationGHSA-qg3f-hm4x-h5h8 Published Yesterday

54

Medium Risk

This Affects:

PHPverbb/formie
0.0.1 - 3.1.43
Fixed in 3.1.44
Are you affected? Scan for Free

TL;DR

Formie's save-as-stencil action writes a form's settings into the shared Project Config without checking whether the requesting Control Panel user holds the required permission. Any authenticated Control Panel user, regardless of their assigned Formie permissions, can trigger this action and write to Project Config. The fix adds a permission check before the action writes to Project Config.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you grant Control Panel access to users without full administrative permissions.

Background info

verbb/formie is vulnerable to Missing Authorization in versions 0.0.1 - 3.1.43.

How to fix this

Upgrade the verbb/formie library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform