A vulnerability marked as critical has been reported in HeyForm up to 3.0.0-rc.8. Affected is an unknown function of the file /api/upload. Performing a manipulation results in unrestricted upload.
This vulnerability was named CVE-2026-63429. The attack may be initiated remotely. There is no available exploit.