### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
Update verbb/formie to 3.1.24; verbb/formie to 2.2.20 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanFormie: Pre-authenticated server-side template injection in Hidden fields affects verbb/formie (composer), verbb/formie (composer). Severity is critical. ### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| verbb/formiecomposer | >=3.0.0-beta.1,<3.1.24 | 3.1.24 |
| verbb/formiecomposer | <2.2.20 | 2.2.20 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate verbb/formie to 3.1.24; verbb/formie to 2.2.20 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanFormie: Pre-authenticated server-side template injection in Hidden fields affects verbb/formie (composer), verbb/formie (composer). Severity is critical. ### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain. ### Patches - [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24) ### Workarounds - Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible - Otherwise, upgrade to patched versions
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| verbb/formiecomposer | >=3.0.0-beta.1,<3.1.24 | 3.1.24 |
| verbb/formiecomposer | <2.2.20 | 2.2.20 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard