Authentication Bypass in Heym Redis Workflow Node by Heym
CVE-2026-100860
6.8MEDIUM
What is CVE-2026-100860?
The Heym product versions prior to 0.0.105 contain a significant flaw in the Redis workflow node that permits an authenticated user to bypass credential authorization. When the system fails to retrieve the appropriate credential due to non-existence or lack of authorization, it erroneously defaults to connecting to localhost:6379 without authentication. This could lead to unintended access, allowing an authenticated workflow author to gain read/write capabilities on the Redis backend, contingent on the deployment configuration.
Affected Version(s)
heym 0 < 0.0.105
heym 0.0.105
