CVE-2026-35198
🟠 Łataj w tym tygodniu
W HeyForm występuje podatność XSS, umożliwiająca przejęcie konta przez niskoprawnego użytkownika.
CVSS
9.0
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue.
privilege-escalation xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-07-20 16:16:58 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-21 20:16:34 UTC |
Referencje
- https://github.com/heyform/heyform/commit/cc97d27a57ae400fec23abf5dcf6f9533c3b5db3 (security-advisories@github.com)
- https://github.com/heyform/heyform/security/advisories/GHSA-chmm-jqpm-3pwx (security-advisories@github.com)
- https://vokecyber.com/research/cve-2026-35198-heyform-stored-xss (security-advisories@github.com)