CVE-2026-52889 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-52889 requires immediate attention.

· 6 min read

Executive Summary

CVE-2026-52889 is a critical Twig template injection issue in verbb/formie for Craft CMS 5. Affected Hidden fields could take request-derived values such as User Agent, Referer, Current URL, Query Parameter, or Cookie Value and pass them into Craft’s Twig rendering layer. On a public form, an unauthenticated attacker may be able to inject Twig syntax and have it evaluated server-side when the form renders.

This is especially dangerous for solo developers and small teams because the attack requires no login, no prior foothold, and can be triggered by a single visit to a public form page. Depending on site configuration and available Twig capabilities, impact may range from sensitive data exposure to application state changes or remote code execution.

Immediate Action

  • Upgrade immediately to verbb/formie 3.1.27 or later. Vendor advisory: TODO: vendor advisory / release notes.
  • Remove or disable any Hidden fields using request-derived defaults on public forms: User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, Cookie Value.
  • Temporarily take public forms offline or switch them to a safe fallback if you cannot patch right away.
  • Rollback only if needed to a known-safe deployment that does not expose the vulnerable form path; do not leave the vulnerable version in production.
  • Review logs for unusual Twig-like payloads in form submissions and public page requests.

Affected Versions

  • verbb/formie@>=3.0.0-beta.1, <=3.1.26 vulnerable on Craft 5
  • verbb/formie@3.1.27 patched
  • verbb/formie@3.1.27+ safe target

Resolution Guide

JavaScript package managers (if your project installs Formie through a package lock or monorepo workflow):

# npm
npm install verbb/formie@3.1.27

# yarn
yarn add verbb/formie@3.1.27

# pnpm
pnpm add verbb/formie@3.1.27

Python tooling is generally not applicable to Craft/Formie, but if you mirror dependencies in automation, update the deployment manifest to the patched version and redeploy.

Java ecosystems are not typically used for this package, but the same rule applies: pin the patched release in your build/deploy manifest and rebuild the image or artifact.

Linux package managers:

# apt/yum do not usually manage Craft plugins directly.
# Update via your app's dependency workflow, then redeploy the application.

Docker:

# Rebuild with the patched dependency version
docker build --no-cache -t your-app:patched .

# Deploy the new image
docker run -d --name your-app your-app:patched

Config hardening:

# Disable or remove request-derived Hidden field defaults in public forms
# Safe alternatives: static values or admin-authored custom defaults only

# Example policy:
# - Allow: custom default
# - Block: user agent, referer, current URL, query parameter, cookie value

Minimal code/config fix example:

// Pseudocode: avoid passing request-derived values into Twig rendering
$allowedDefault = $field->defaultValueType === 'custom'
    ? $field->defaultValue
    : (string) $field->defaultValue; // treat request-derived values as plain text

return $this->renderHiddenField($allowedDefault);

Detection & Verification

Check installed version:

composer show verbb/formie
composer show verbb/formie --all | grep -E 'versions|name'

Check your lockfile and deployment manifests:

grep -R "verbb/formie" composer.lock composer.json .

Find risky form configuration:

# Search for Hidden fields and request-derived defaults in project config
grep -R "Hidden\|User Agent\|Referer\|Current URL\|Query Parameter\|Cookie Value" config/ storage/ vendor/ -n

Dependency audit:

composer audit
composer outdated verbb/formie

Verify the fix:

# Confirm the patched version is installed
composer show verbb/formie | grep versions

# Confirm no vulnerable version remains in the lockfile
grep -n "verbb/formie" composer.lock

If you can safely test in a staging environment, submit a public form with a request header or query string containing Twig-like syntax and confirm it is treated as plain text, not evaluated.

Risk and Impact

This flaw can let an unauthenticated attacker make the server evaluate attacker-controlled Twig when a public form is rendered. In the worst case, that can expose secrets, alter application behavior, or lead to remote code execution depending on the Twig environment and what objects are available.

The blast radius is highest for sites with public forms that use Hidden fields and request-derived defaults. Small teams should treat this as an emergency patch because exploitation can be triggered remotely with a single crafted request.

Keep reading