{"id":"CVE-2025-67718","aliases":["GHSA-m654-769v-qjv7"],"url":"https://o3.security/vulnerability/CVE-2025-67718","summary":"Formio improperly authorized permission elevation through specially crafted request path","details":"# Security Advisory: Unauthorized permission elevation through specially crafted request path\n\n**Summary:** A flaw in path handling could allow an attacker to access protected API endpoints by sending a crafted request path. This issue could result in unauthorized data disclosure under certain configurations.\n\n**Impact:** In affected configurations, an unauthenticated or unauthorized request could retrieve data from endpoints that should be protected.\n\n**Affected versions:** \n<= 3.5.6\n<= 4.4.2\n\n**Fixed in:** \n3.5.7\n4.4.3\n\n**Mitigation / Workarounds:** \nUpgrade to 3.5.7  or later. \n\n**Disclosure timeline:** \nDiscovered 2025-05-22; fixed 2025-05-30; publicly disclosed 2025-12.","published":"2025-12-11T00:58:43.297Z","modified":"2026-08-12T03:51:27.053302220Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"formio","fixedVersion":"3.5.7"},{"ecosystem":"npm","name":"formio","fixedVersion":"4.4.3"}],"fix":{"url":"https://github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478","label":"formio/formio@1836bdd"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67718.json"},{"type":"ADVISORY","url":"https://github.com/formio/formio/security/advisories/GHSA-m654-769v-qjv7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67718"},{"type":"FIX","url":"https://github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478"},{"type":"WEB","url":"https://github.com/formio/formio/commit/1665b7c99e3cf3246db7ff0b4ff732231dc6903b"},{"type":"PACKAGE","url":"https://github.com/formio/formio"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.053302220Z"}}