CVE-2026-82291CWE-942

CVE-2026-82291

High · published August 29, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
22.3
In the wild
Unconfirmed
What it is

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00300 · 22.3th percentile
Weakness
CWE-942 · Permissive Cross-domain Security Policy with Untrusted Domains
Published
2026-08-29T00:20Z
References (6)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 28 AUG 16:19Z
    HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials
    cvelistv5