A vulnerability classified as critical has been found in HeyForm up to 3.0.0-rc.8. Affected by this issue is some unknown functionality of the component completeSubmission. The manipulation of the argument hiddenFields leads to improper input validation.

This vulnerability is referenced as CVE-2026-63428. Remote exploitation of the attack is possible. No exploit is available.