Multiple Security Flaws in Heym Product by Heym
CVE-2026-100865
What is CVE-2026-100865?
The Heym platform prior to version 0.0.53 suffers from critical vulnerabilities, allowing potential attakers to exploit various pathways for arbitrary code execution and unauthorized access. The lack of an effective sandbox for the Python eval() in the workflow condition evaluator can lead to arbitrary code execution by users capable of altering workflow conditions or templates. Furthermore, insufficient verification during Slack and Telegram webhook actions allows anyone familiar with the public URL to trigger workflows without authentication. Additionally, a security flaw in the OAuth authorization endpoint permits attackers to create malicious redirects, leading to the execution of attacker-controlled scripts. Lastly, sensitive tokens and session data are stored in plaintext, heightening the risk of exposing valid access tokens following a database breach.
Affected Version(s)
heym 0 < 0.0.53
heym 0.0.53
