Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. verbb/formie
  4. ›
  5. CVE-2026-52889

CVE-2026-52889: Formie Hidden field defaults vulnerable to Server-Side Template Injection

July 6, 2026

Formie Hidden fields could evaluate request-derived values as Twig during front-end form rendering.

When a Hidden field used a dynamic default value such as HTTP User Agent, Referer URL, Current URL, Query Parameter, or Cookie Value, the value was copied from the incoming request and later passed to Craft’s Twig rendering layer. This allowed an unauthenticated attacker to provide Twig syntax in request-controlled input and have it evaluated server-side when the form was rendered.

References

  • github.com/advisories/GHSA-565m-g33j-jq96
  • github.com/verbb/formie/security/advisories/GHSA-565m-g33j-jq96
  • nvd.nist.gov/vuln/detail/CVE-2026-52889

Code Behaviors & Features

Detect and mitigate CVE-2026-52889 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.1.27

Fixed versions

  • 3.1.27

Solution

Upgrade to version 3.1.27 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine

Source file

packagist/verbb/formie/CVE-2026-52889.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 21 Jul 2026 00:18:08 +0000.