Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-52889: Formie Hidden field defaults vulnerable to server-side code execution
GHSA-565m-g33j-jq96
CVE-2026-52889
Summary
An unauthenticated attacker can execute server-side code by visiting a public form with a hidden field that uses a dynamic default value. This could lead to sensitive information disclosure, application state modification, or even remote code execution. To fix this, update Formie to version 3.1.27 or later.
What to do
- Update verbb formie to version 3.1.27.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| composer | verbb | formie |
< 3.1.27 Fix: upgrade to 3.1.27
|
Original title
Formie Hidden field defaults vulnerable to Server-Side Template Injection
Original description
## Summary
Formie Hidden fields could evaluate request-derived values as Twig during front-end form rendering.
When a Hidden field used a dynamic default value such as HTTP User Agent, Referer URL, Current URL, Query Parameter, or Cookie Value, the value was copied from the incoming request and later passed to Craft’s Twig rendering layer. This allowed an unauthenticated attacker to provide Twig syntax in request-controlled input and have it evaluated server-side when the form was rendered.
## Affected Versions
`verbb/formie` for Craft 5:
- Affected: >= 3.0.0-beta.1, <= 3.1.26
- Patched: 3.1.27
## Impact
An unauthenticated attacker could trigger server-side template evaluation by visiting a public form containing a Hidden field configured with a request-derived default value.
Because Craft’s normal Twig environment exposes application objects, this may lead to disclosure of sensitive information, modification of application state, or remote code execution depending on the site configuration and available Twig capabilities.
## Technical Details
The issue exists in the Hidden field front-end render path. Request-derived Hidden field defaults were assigned to the field’s defaultValue, then rendered via Twig in `Hidden::getFrontEndInputOptions()`.
The fix ensures Twig rendering is only performed for the custom default option, where the template source is admin-authored. Request-derived default options are now treated as plain strings.
## Patches
Update to Formie 3.1.27 or later.
## Workarounds
Until patched, avoid using request-derived Hidden field defaults on public forms, including:
- HTTP User Agent
- HTTP Refer URL
- Current URL
- Current URL without Query String
- Query Parameter
- Cookie Value
Alternatively, remove affected Hidden fields from public forms until the update is applied.
## Credit
Name: Yanchon918s
Email: [[email protected]](mailto:[email protected])
Formie Hidden fields could evaluate request-derived values as Twig during front-end form rendering.
When a Hidden field used a dynamic default value such as HTTP User Agent, Referer URL, Current URL, Query Parameter, or Cookie Value, the value was copied from the incoming request and later passed to Craft’s Twig rendering layer. This allowed an unauthenticated attacker to provide Twig syntax in request-controlled input and have it evaluated server-side when the form was rendered.
## Affected Versions
`verbb/formie` for Craft 5:
- Affected: >= 3.0.0-beta.1, <= 3.1.26
- Patched: 3.1.27
## Impact
An unauthenticated attacker could trigger server-side template evaluation by visiting a public form containing a Hidden field configured with a request-derived default value.
Because Craft’s normal Twig environment exposes application objects, this may lead to disclosure of sensitive information, modification of application state, or remote code execution depending on the site configuration and available Twig capabilities.
## Technical Details
The issue exists in the Hidden field front-end render path. Request-derived Hidden field defaults were assigned to the field’s defaultValue, then rendered via Twig in `Hidden::getFrontEndInputOptions()`.
The fix ensures Twig rendering is only performed for the custom default option, where the template source is admin-authored. Request-derived default options are now treated as plain strings.
## Patches
Update to Formie 3.1.27 or later.
## Workarounds
Until patched, avoid using request-derived Hidden field defaults on public forms, including:
- HTTP User Agent
- HTTP Refer URL
- Current URL
- Current URL without Query String
- Query Parameter
- Cookie Value
Alternatively, remove affected Hidden fields from public forms until the update is applied.
## Credit
Name: Yanchon918s
Email: [[email protected]](mailto:[email protected])
ghsa CVSS3.1
9.8
Vulnerability type
CWE-1336
Published: 6 Jul 2026 · Updated: 6 Jul 2026 · First seen: 6 Jul 2026