{"id":"CVE-2025-67718","summary":"Formio improperly authorized permission elevation through specially crafted request path","details":"Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized request could retrieve data from endpoints that should be protected. This issue is fixed in versions 3.5.7 and 4.4.3.","aliases":["GHSA-m654-769v-qjv7"],"modified":"2026-08-12T03:51:27.053302220Z","published":"2025-12-11T00:58:43.297Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-178","CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67718.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67718.json"},{"type":"ADVISORY","url":"https://github.com/formio/formio/security/advisories/GHSA-m654-769v-qjv7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67718"},{"type":"FIX","url":"https://github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/formio/formio","events":[{"introduced":"e16408ac22f759fce2eb95c4775e501af42c92de"},{"fixed":"91c7bb233774b32d0d616fb0727ef450567542b6"},{"fixed":"1836bdd9f55f5888ff397c257b2108c09d3de478"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0-rc.1"},{"fixed":"4.4.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v4.3.0","v4.4.2","v4.4.2-rc.7","v4.4.2-rc.6","v4.4.2-rc.5","v4.4.2-rc.4","v4.4.2-rc.3","v4.4.2-rc.2","v4.4.2-rc.1","v4.4.1-rc.1","v4.4.0","v4.4.0-rc.38","v4.4.0-rc.37","v4.4.0-rc.36","v4.4.0-rc.35","v4.4.0-rc.34","v4.4.0-rc.33","v4.4.0-rc.32","v4.4.0-rc.31","v4.4.0-rc.30","v4.4.0-rc.29","v4.4.0-rc.28","v4.4.0-rc.27","v4.4.0-rc.26","v4.4.0-rc.25","v4.4.0-rc.24","v4.4.0-rc.23","v4.4.0-rc.22","v4.4.0-rc.21","v4.4.0-rc.20","v4.4.0-rc.19","v4.4.0-rc.18","v4.4.0-rc.17","v4.4.0-rc.16","v4.4.0-rc.15","v4.4.0-rc.14","v4.4.0-rc.13","v4.4.0-rc.12","v4.4.0-rc.9","v4.4.0-rc.8","v4.4.0-rc.7","v4.4.0-rc.6","v4.4.0-rc.5","v4.4.0-rc.4","v4.4.0-rc.3","v4.4.0-rc.2","v4.4.0-rc.1","v4.3.0-rc.38","v4.3.0-rc.37","v4.3.0-rc.36","v4.3.0-rc.35","v4.3.0-rc.34","v4.3.0-rc.33","v4.3.0-rc.32","v4.3.0-rc.31","v4.3.0-rc.30","v4.3.0-rc.29","v4.3.0-rc.28","v4.3.0-rc.27","v4.3.0-rc.26","v4.3.0-rc.25","v4.3.0-rc.24","v4.3.0-rc.23","v4.3.0-rc.22","v4.3.0-rc.21","v4.3.0-rc.20","v4.3.0-rc.19","v4.3.0-rc.18","v4.3.0-rc.17","v4.3.0-rc.16","v4.3.0-rc.15","v4.3.0-rc.14","v4.3.0-rc.13","v4.3.0-rc.12","v4.3.0-rc.11","v4.3.0-rc.10","v4.3.0-rc.9","v4.3.0-rc.8","v4.3.0-rc.7","v4.3.0-rc.6","v4.2.1-rc.5","v4.3.0-rc.5","v4.3.0-rc.4","v4.3.0-rc.3","v4.3.0-rc.2","v4.2.1-rc.4","v4.2.1-rc.3","v4.2.1-rc.1","v4.2.0","v4.2.0-rc.6","v4.2.0-rc.5","v4.2.0-rc.4","v4.2.0-rc.3","v4.2.0-rc.2","v4.2.0-rc.1","v4.1.0-rc.4","v4.1.0-rc.3","v4.1.0-rc.2","v4.1.0-rc.1","v4.0.0","v4.0.0-rc.33","v4.0.0-rc.32","v4.0.0-rc.31","v4.0.0-rc.30","v4.0.0-rc.29","v4.0.0-rc.27","v4.0.0-rc.26","v4.0.0-rc.25","v4.0.0-rc.24","v4.0.0-rc.23","v4.0.0-rc.22","v4.0.0-rc.21","v4.0.0-rc.20","v4.0.0-rc.19","v4.0.0-rc.18","v4.0.0-rc.17","v4.0.0-rc.16","v4.0.0-rc.15","v4.0.0-rc.14","v4.0.0-rc.13","v4.0.0-rc.12","v4.0.0-rc.11","v4.0.0-rc.10","v4.0.0-rc.9","v4.0.0-rc.8","v4.0.0-rc.7","v4.0.0-rc.6","v4.0.0-rc.5","v4.0.0-rc.4","v4.0.0-rc.3","v4.0.0-rc.2","v4.0.0-rc.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-67718.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}