Credential Exfiltration Vulnerability in Heym by Heymrun
CVE-2026-100859

7.1HIGH

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100859?

The Heym product prior to version 0.0.106 is vulnerable to a credential exfiltration issue due to insecure handling of credentials via an API endpoint. Collaborators who have access to shared credentials can exploit the vulnerability by overriding the destination URL in the config parameter. As a result, this flaw allows malicious actors to redirect the server into sending decrypted authentication secrets to attacker-controlled endpoints, potentially compromising sensitive information.

Affected Version(s)

heym 0 < 0.0.106

heym 0.0.106

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

roonakyadav
mbakgun
.