CVE-2025-65956 Overview
Formwork is a flat file-based Content Management System (CMS). CVE-2025-65956 is a stored cross-site scripting (XSS) vulnerability affecting Formwork versions prior to 2.2.0. The flaw stems from inserting unsanitized data into the blog tag field. Any authenticated user who accesses or edits an affected blog post triggers attacker-controlled script execution in their browser. The issue is persistent and impacts privileged administrative workflows. Maintainers patched the vulnerability in version 2.2.0.
Critical Impact
Attackers with low-privileged CMS credentials can plant persistent JavaScript payloads that execute in administrator browsers, enabling session theft and administrative action hijacking through the Formwork panel.
Affected Products
- Formwork CMS versions prior to 2.2.0
- formwork_project:formwork package distributions
- Formwork panel administrative interface
Discovery Timeline
- 2025-11-26 - CVE-2025-65956 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-65956
Vulnerability Analysis
The vulnerability is a stored cross-site scripting flaw [CWE-79] in the Formwork panel. The blog tag field accepts user input without proper sanitization or output encoding. When the panel renders a blog post that contains a crafted tag, the browser interprets the injected markup as executable script.
Exploitation requires an authenticated account with permission to create or edit blog posts. The payload persists in the flat-file storage and runs each time an administrator or editor loads the affected post. The vulnerability has a scope change: code executes in the administrative context, so an attacker with lower privileges can target users with higher privileges.
Root Cause
The root cause is missing HTML escaping when rendering user-supplied blog tag values in the panel UI. Patch commit 4abcd60ae7692b46d316f956b0b20fb85336f3b2 introduces the escapeHtml helper and replaces direct innerHTML assignments with innerText in panel components. Prior to the fix, strings written through innerHTML allowed arbitrary HTML and <script> constructs to reach the DOM.
Attack Vector
An authenticated attacker submits a blog tag containing JavaScript payload markup. The value is stored in Formwork's flat-file content. When an administrator opens the affected post in the panel, the browser renders the tag unescaped, executing the payload under the admin session's origin. Common impacts include session cookie theft, CSRF-style actions through the panel API, and persistence through additional user or configuration changes.
// Patch excerpt: panel/src/ts/components/fileslist.ts
import { $, $$ } from "../utils/selectors";
-import { escapeRegExp, makeDiacriticsRegExp } from "../utils/validation";
+import { escapeHtml, escapeRegExp, makeDiacriticsRegExp } from "../utils/validation";
import { app } from "../app";
import { debounce } from "../utils/events";
import { Form } from "./form";
// Patch excerpt: panel/src/ts/components/inputs/color-input.ts
if (outputElement) {
const updateValueLabel = (element: HTMLInputElement) => {
- outputElement.innerHTML = element.value;
+ outputElement.innerText = element.value;
};
Source: Formwork patch commit 4abcd60
Detection Methods for CVE-2025-65956
Indicators of Compromise
- Blog tag fields in Formwork content files containing HTML tags, <script> elements, on*= event handler attributes, or javascript: URIs.
- Unexpected outbound requests from panel user browsers to attacker-controlled domains while editing or viewing posts.
- Panel user sessions showing anomalous API calls that correspond to viewing blog posts with suspicious tag content.
Detection Strategies
- Grep the Formwork content directory for stored tag values containing <, >, script, onerror, or onload substrings.
- Review web server access logs for POST requests to the panel blog edit endpoints submitting non-alphanumeric tag payloads.
- Inspect browser Content Security Policy (CSP) violation reports originating from the panel UI.
Monitoring Recommendations
- Enable and monitor CSP report-only or enforcing headers on the Formwork panel to surface injected inline scripts.
- Alert on new or modified blog post files with tag fields that fail an allowlist of alphanumeric and hyphen characters.
- Audit panel account activity for low-privilege users creating or editing content shortly before administrator sessions.
How to Mitigate CVE-2025-65956
Immediate Actions Required
- Upgrade Formwork to version 2.2.0 or later across all production and staging environments.
- Audit existing blog posts and tag fields for HTML or JavaScript content and remove any suspicious entries.
- Rotate panel user session cookies and credentials for administrators who may have viewed affected posts.
Patch Information
The fix is delivered in Formwork 2.2.0 via pull request #791 and commit 4abcd60. The patch introduces the escapeHtml helper for panel-rendered strings and replaces unsafe innerHTML assignments with innerText. See the GitHub Security Advisory GHSA-7j46-f57w-76pj for full disclosure details.
Workarounds
- Restrict blog post creation and editing permissions to a minimal set of trusted panel users until the upgrade is applied.
- Deploy a strict Content Security Policy on the Formwork panel that forbids inline scripts and untrusted script sources.
- Place the panel behind an authenticating reverse proxy or IP allowlist to limit exposure of administrative users.
# Example: enforce a restrictive CSP on the Formwork panel via nginx
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.