HeyForm patched a high-severity vulnerability, tracked as CVE-2026-63429, that allowed unauthenticated users to upload arbitrary files through the POST /api/upload endpoint and receive a permanent public URL hosted on the HeyForm domain. The flaw affected versions prior to 3.0.0-rc.9 and stemmed from missing authentication, session validation, form-context checks, and openToken enforcement, enabling remote abuse by any internet user to store files up to 10 MB without authorization. The issue was classified under CWE-306 and CWE-434 and assigned a CVSS 8.6 severity rating.
The fix landed in HeyForm’s security hardening update, which restricted anonymous uploads to valid form contexts, enforced token validation, limited uploads to approved form fields, and added cleanup for unauthorized files. The same update also tightened related security controls by improving sanitization of obfuscated javascript:, vbscript:, and data: URLs, reducing HTML and CSS injection risks, strengthening outbound request protections against SSRF and DNS rebinding, and binding open tokens to form IDs to prevent unauthorized field injection. Users were advised to upgrade to 3.0.0-rc.9 or later.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-63429 was disclosed as a high-severity vulnerability affecting HeyForm versions prior to 3.0.0-rc.9, where an unauthenticated /api/upload endpoint allowed arbitrary file uploads and returned permanent public URLs. The disclosure states the issue was patched in version 3.0.0-rc.9 and advises users to upgrade.
A HeyForm GitHub commit titled "fix: harden form security surfaces" introduced protections including restricting anonymous uploads to valid form context with token validation, tightening submission handling, improving sanitization, and adding SSRF/DNS rebinding defenses. The commit also added and updated tests covering the new security checks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.