{"id":"CVE-2026-82291","title":"HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication","summary":"HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visit…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-942"],"published":"2026-08-28","updated":"2026-09-16","sourceUpdated":"2026-09-16T13:42:44.547","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82291","references":[{"url":"https://github.com/heyform/heyform","label":"disclosure@vulncheck.com"},{"url":"https://github.com/heyform/heyform/blob/v3.0.0-rc.7/packages/server/src/main.ts","label":"disclosure@vulncheck.com"},{"url":"https://github.com/heyform/heyform/commit/bf9d738ca70ae5641c0c7372982b00365c5144d4","label":"disclosure@vulncheck.com"},{"url":"https://github.com/heyform/heyform/security/advisories/GHSA-fg7j-rmgr-rc9g","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/heyform-reflects-any-origin-in-cors-responses-while-allowing-credentials","label":"disclosure@vulncheck.com"},{"url":"https://github.com/heyform/heyform/security/advisories/GHSA-fg7j-rmgr-rc9g","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.003,"epssPercentile":0.22879,"ingestedAt":"2026-09-16T13:56:12.599Z","slug":"CVE-2026-82291","body":"## Overview\n\nHeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}