PatchSiren cyber security CVE debrief
CVE-2026-35198 heyform CVE debrief
A stored cross-site scripting (XSS) vulnerability in HeyForm's form builder allows low-privileged team members to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. The issue was patched in version 3.0.0-rc.7. This vulnerability affects users of HeyForm, especially those with low-privileged team members, and could lead to account takeovers if not addressed. The vulnerability exists due to insufficient input validation and sanitization in the form builder feature.
- Vendor
- heyform
- Product
- Unknown
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-20
Who should care
Users of HeyForm, especially those with low-privileged team members, should be aware of this vulnerability and ensure they are using version 3.0.0-rc.7 or later to prevent potential account takeovers. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.
Technical summary
The vulnerability exists in the form builder of HeyForm, allowing low-privileged team members to inject malicious JavaScript. This JavaScript executes when a team owner views the form, potentially leading to complete account takeover. The vulnerability was patched in version 3.0.0-rc.7. Affected product deployments should be verified, and compensating controls should be reviewed while remediation is scheduled and verified.
Defensive priority
High
Recommended defensive actions
- Update HeyForm to version 3.0.0-rc.7 or later
- Restrict form building privileges to trusted team members
- Monitor form usage and team member activity
- Implement additional security measures to prevent account takeover
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-20T16:16:58.440Z and last modified on 2026-07-20T19:17:21.537Z. The NVD entry is currently being reviewed. A stored cross-site scripting (XSS) vulnerability in HeyForm's form builder allows low-privileged team members to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. The issue was patched in version 3.0.0-rc.7. Evidence limits suggest that affected deployments and configurations should be verified with the vendor and through internal reviews.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T16:16:58.440Z and has not been modified since then.