heymrun heym
12 known vulnerabilities in heymrun heym, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105396 CVSS 5.3 medium Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect…
- CVE-2026-101050 CVSS 8.3 high Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent…
- CVE-2026-101049 CVSS 8.3 high Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote…
- CVE-2026-100865 CVSS 8.7 high Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor…
- CVE-2026-100864 CVSS 8.7 high heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows…
- CVE-2026-100863 CVSS 5.3 medium Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py…
- CVE-2026-100862 CVSS 6.9 medium heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected…
- CVE-2026-100861 CVSS 5.3 medium heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated…
- CVE-2026-100860 CVSS 6.8 medium heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node…
- CVE-2026-100859 CVSS 7.1 high Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators…
- CVE-2026-100858 CVSS 7.6 high heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes…
- CVE-2026-84207 CVSS 5.3 medium Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to…