Intel

AIKIDO-2026-812289

solspace/craft-freeform is vulnerable to Missing Authorization

Missing AuthorizationGHSA-5wqp-7h55-q86m Published Yesterday

43

Medium Risk

This Affects:

PHPsolspace/craft-freeform
5.0.0 - 5.15.26
Fixed in 5.15.27
Are you affected? Scan for Free

TL;DR

Two Control Panel API endpoints in Freeform return data without enforcing the corresponding Freeform permission. The asset card thumbnail endpoint exposes asset metadata such as IDs, titles, filenames, and URLs, and the notification template endpoint exposes template subjects, bodies, sender and reply-to details, and recipient addresses. Any signed-in Craft user with Control Panel access can read this data even without the forms-access or notifications-access permission, disclosing notification template contents and asset details. The fix adds the required permission checks to both endpoints before returning data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have Craft users with Control Panel access who lack the relevant Freeform permissions.

Background info

solspace/craft-freeform is vulnerable to Missing Authorization in versions 5.0.0 - 5.15.26.

How to fix this

Upgrade the solspace/craft-freeform library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform