cbcvebase.

Heymrun Heym vulnerabilities

15 known vulnerabilities affecting heymrun/heym.

Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM10

Vulnerabilities

Page 1 of 1
CVE-2026-100864P2HIGHCVSS 8.8fixed in 0.0.912026-09-27
CVE-2026-100864 [HIGH] CWE-94 CVE-2026-100864: heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/fi heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fallback resolver to access os.system and execute comman
nvd
CVE-2026-100865P2HIGHCVSS 8.8fixed in 0.0.532026-09-27
CVE-2026-100865 [HIGH] CWE-94 CVE-2026-100865: Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.
nvd
CVE-2026-45227P3HIGHCVSS 8.8fixed in 0.0.212026-05-12
CVE-2026-45227 [HIGH] CWE-693 CVE-2026-45227: Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that a Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __import__ function, import blocked modules such as os and
nvd
CVE-2026-45225P3HIGHCVSS 7.6fixed in 0.0.212026-05-12
CVE-2026-45225 [HIGH] CWE-22 CVE-2026-45225: Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows a Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted filename with traversal sequences. Attackers can exploit the unvalidated filename parameter in the upload_file() handler to bypass path restrictions and w
nvd
CVE-2026-45226P3HIGHCVSS 7.1fixed in 0.0.212026-05-12
CVE-2026-45226 [HIGH] CWE-863 CVE-2026-45226: Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute thos
nvd
CVE-2026-101050P3MEDIUMCVSS 6.5fixed in 0.0.532026-09-27
CVE-2026-101050 [MEDIUM] CWE-287 CVE-2026-101050: Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook en Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured credentials and execute actions on attacker-supplied input.
nvd
CVE-2026-100858P3MEDIUMCVSS 6.8fixed in 0.0.1092026-09-27
CVE-2026-100858 [MEDIUM] CWE-918 CVE-2026-100858: heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP no
nvd
CVE-2026-100859P3MEDIUMCVSS 6.5fixed in 0.0.1062026-09-27
CVE-2026-100859 [MEDIUM] CWE-918 CVE-2026-100859: Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/te Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attac
nvd
CVE-2026-101049P3MEDIUMCVSS 6.5fixed in 0.0.532026-09-27
CVE-2026-101049 [MEDIUM] CWE-287 CVE-2026-101049: Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs o Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.
nvd
CVE-2026-84207P4MEDIUMCVSS 5.4fixed in 0.0.982026-09-01
CVE-2026-84207 [MEDIUM] CWE-918 CVE-2026-84207: Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach internal services and read responses from the WebSocket Trigger node.
nvd
CVE-2026-105396P4MEDIUMCVSS 5.4fixed in 0.0.1122026-10-05
CVE-2026-105396 [MEDIUM] CWE-346 CVE-2026-105396: Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows u Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to
nvd
CVE-2026-100863P4MEDIUMCVSS 5.0fixed in 0.0.912026-09-27
CVE-2026-100863 [MEDIUM] CWE-918 CVE-2026-100863: Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both re Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme check and bypassing the egress-pinning HTTP client;
nvd
CVE-2026-100861P4MEDIUMCVSS 5.0fixed in 0.0.1052026-09-27
CVE-2026-100861 [MEDIUM] CWE-918 CVE-2026-100861: heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplie heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output.
nvd
CVE-2026-100862P4MEDIUMCVSS 4.9fixed in 0.0.912026-09-27
CVE-2026-100862 [MEDIUM] CWE-312 CVE-2026-100862: heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persisted unsanitized into execution history), MCP API keys (stored as a plaintext column, returned in config/list r
nvd
CVE-2026-100860P4MEDIUMCVSS 5.5fixed in 0.0.1052026-09-27
CVE-2026-100860 [MEDIUM] CWE-636 CVE-2026-100860: heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis w heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None — because the credential ID does not exist or the caller is not authorized to use it — the node treats the lookup failure as an empt
nvd
Heymrun Heym vulnerabilities | cvebase