CVE-2026-76086: Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
### Impact The control panel action `formie/integrations/form-settings` (`IntegrationsController::actionFormSettings`) was reachable by any authenticated user without the appropriate form integration permissions. The action applied request-supplied settings to a fully configured integration via `setAttributes($settings, false)`, allowing an attacker to overwrite outbound host properties (e.g. `apiUrl`) while the server sent stored API keys or OAuth tokens to the attacker-controlled host. The remote response was returned in the JSON body (non-blind SSRF). This is an incomplete remediation of [GHSA-cvpc-hccg-wmw4](https://github.com/advisories?query=GHSA-cvpc-hccg-wmw4). The `form-settings` action was excluded from the permission gate added in 3.1.28. Any site where a low-privileged user can authenticate (including front-end members on sites with public registration) could exfiltrate CRM/email-marketing/webhook integration credentials and probe internal network endpoints. ### Patches Fixed in **3.1.31** (Craft 5) and **2.2.23** (Craft 4). The action now requires a CP request, a valid `formId`, and form integration permissions (`formie-showFormIntegrations` / per-form variant on Craft 5; `formie-manageFormIntegrations` / per-form variant on Craft 4). Request settings are filtered to an allowlist; URL, host, and credential properties cannot be overridden from user input. ### Workarounds Restrict front-end user registration and limit CP access until upgraded. No configuration-only workaround fully mitigates the issue. - Reported by Jorge González ([email protected])
Recommended action
Recommended action
Upgrade affected packages to a patched version: verbb/formie 3.1.31, verbb/formie 2.2.23.
Technical details
- Vendor
- Not specified
- Product
- verbb/formie
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source