Plaintext Secret Storage Vulnerability in heym Workflow Automation Platform
CVE-2026-100862
6.9MEDIUM
What is CVE-2026-100862?
The heym Workflow Automation Platform is vulnerable to a serious issue where multiple sensitive credentials, such as webhook header-auth values, MCP API keys, and session tokens, are stored and returned in plaintext. This vulnerability exists in all versions prior to 0.0.91, exposing highly confidential information in execution histories and logs. Users with access to workflow data, including team members or anyone able to read backups, can exploit these plaintext secrets to hijack workflows or impersonate authorized users. Immediate updates are advised to mitigate this risk and protect sensitive information.
Affected Version(s)
heym 0 < 0.0.91
heym 0.0.91
