Impact
The bug causes HeyForm to reflect the Origin header in CORS responses while allowing credentials. This misconfiguration lets an attacker host a malicious page that a logged‑in user visits, enabling the attacker to run authenticated GraphQL queries from that origin. The attacker can read or modify sensitive data such as workspaces, projects, forms, submissions, and respondent information, or change account settings.
Affected Systems
All HeyForm installations running a version earlier than 3.0.0‑rc.8 are affected. The vulnerability exists in the server code before the 3.0.0‑rc.8 release and applies to all deployments of the HeyForm product.
Risk and Exploitability
The CVSS score of 8.1 classifies this issue as high severity. EPSS is not available, so the probability of exploitation cannot be quantified from the current data, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need a user who is already authenticated to the application to act through a malicious origin page. With proper credentials, the attacker can query or modify protected data such as workspaces, projects, forms, submissions, and respondent information.
OpenCVE Enrichment