Sceawere
Vulnerability Detail
CVE-2026-105950UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Formwork Cross-Site Scripting Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 9h ago
- Vendor
- getformwork
- Product
- formwork
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.3.13 is recommended to address this issue. The name of the patch is 729701e59c5886685c5a1d477bdc3035e41f18b1. Upgrading the affected component is advised.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-10-06T16:17:06.697Z",
"pubdate": "2026-10-06T16:17:06.697Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the URI Sanitizer component of getformwork formwork versions up to 2.3.12.\nThe vulnerability originates from insufficient input validation within the DomSanitizer::sanitizeNodeAttribute function, specifically regarding the handling of the formaction attribute.\nThis flaw allows remote attackers to inject malicious scripts into the application, which are then executed within the context of a victim's browser session.\nSuccessful exploitation can lead to unauthorized access to sensitive user data, session hijacking, or the execution of arbitrary actions on behalf of the authenticated user.\nThe risk is significant as it affects the core sanitization logic, and no special authentication is required for remote exploitation.\nUsers are strongly advised to upgrade to version 2.3.13 or apply the specified patch to remediate this security risk.",
"technicalDetails": "The vulnerability resides in the formwork/src/Sanitizer/DomSanitizer.php file within the DomSanitizer::sanitizeNodeAttribute function. The URI Sanitizer component fails to adequately sanitize the formaction attribute used in HTML elements, such as buttons or inputs. The formaction attribute is designed to specify the URL to which a form should be submitted. When the sanitizer fails to properly validate or block pseudo-protocols like 'javascript:' within this attribute, it creates a conduit for XSS.\nThe exploitation flow initiates when a remote attacker provides a crafted input containing a 'javascript:' URI in the formaction attribute. Because the DomSanitizer component does not filter this payload, the malicious string is rendered into the DOM. When a user interacts with the compromised element, the browser interprets the URI schema and executes the embedded JavaScript payload in the victim's security context.\nSince the execution occurs within the origin of the vulnerable application, the attacker gains the ability to bypass Same-Origin Policy (SOP) protections for that specific context. This allows for the theft of session cookies, sensitive information stored in local storage, or the performance of unauthorized actions by leveraging the user's active session. The lack of proper denylisting or structural validation of the attribute value is the root cause of this injection flaw.\nThe attack is remotely exploitable without the need for prior authentication or elevated privileges, provided the attacker can influence the content processed by the DomSanitizer. The vulnerability affects all versions of getformwork formwork up to and including 2.3.12. The remediation, identified by patch 729701e59c5886685c5a1d477bdc3035e41f18b1, implements stricter validation logic to ensure that only safe, expected URI protocols are permitted within the formaction attribute, effectively neutralizing the injection vector."
}