formie's unauthenticated front-end submission editing can overwrite existing submissions
Package
Affected versions
>= 3.0.0, < 3.1.26
< 2.2.21
Patched versions
3.1.26
2.2.21
Description
Published by the National Vulnerability Database
May 29, 2026
Published to the GitHub Advisory Database
May 29, 2026
Reviewed
May 29, 2026
Last updated
May 29, 2026
Impact
Unauthenticated users could modify existing submissions by posting a known or guessed submission ID to
formie/submissions/save-submission.Patches
2.2.21, 3.1.26
Workarounds
Block unauthenticated access to
actions/formie/submissions/save-submission, or disable/customize front-end submission editing until patched.Credit
formie extends many thanks to:
References