Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v3f3-cmj4-cvj9 | Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials |
Wed, 23 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while the server uses stored API keys or OAuth tokens, causing non-blind server-side requests to an attacker-controlled or internal host and returning the remote response. This residual flaw remained because the permission gate added in version 3.1.28 excluded the form-settings action. Sites that permit low-privileged or front-end user authentication can therefore expose integration credentials and internal network responses. This issue is fixed in versions 2.2.23 and 3.1.31. | |
| Title | Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials | |
| Weaknesses | CWE-862 CWE-915 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T18:32:37.401Z
Reserved: 2026-08-18T21:17:32.200Z
Link: CVE-2026-76086
No data.
Status : Received
Published: 2026-09-23T19:19:14.393
Modified: 2026-09-23T19:19:14.393
Link: CVE-2026-76086
No data.
OpenCVE Enrichment
No data.
Github GHSA