Impact
A stored cross‑site scripting flaw allows low‑privileged team members to embed malicious JavaScript in the title of a form field in HeyForm. When a team owner views the form, the injected script executes in the owner’s browser session, giving the attacker the owner’s privileges and enabling full account takeover.
Affected Systems
The vulnerability affects all open‑source HeyForm releases prior to 3.0.0‑rc.7. Users running earlier releases should verify their version and plan to upgrade.
Risk and Exploitability
The CVSS score of 9 signals critical severity, and the EPSS score of less than 1% indicates low likelihood of exploitation at present, though the flaw is not listed in CISA KEV. The attack vector is low‑privileged form‑editing rights that allow a malicious payload to be stored and later executed when a higher‑privileged user opens the form.
OpenCVE Enrichment