Product
HeyForm versions prior to 3.0.0-rc.8 are vulnerable to a CORS misconfiguration that allows cross-origin authentication, potentially leading to unauthorized data access or account modification.