Multiple Security Flaws in Heym Product by Heym
CVE-2026-100865

8.7HIGH

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100865?

The Heym platform prior to version 0.0.53 suffers from critical vulnerabilities, allowing potential attakers to exploit various pathways for arbitrary code execution and unauthorized access. The lack of an effective sandbox for the Python eval() in the workflow condition evaluator can lead to arbitrary code execution by users capable of altering workflow conditions or templates. Furthermore, insufficient verification during Slack and Telegram webhook actions allows anyone familiar with the public URL to trigger workflows without authentication. Additionally, a security flaw in the OAuth authorization endpoint permits attackers to create malicious redirects, leading to the execution of attacker-controlled scripts. Lastly, sensitive tokens and session data are stored in plaintext, heightening the risk of exposing valid access tokens following a database breach.

Affected Version(s)

heym 0 < 0.0.53

heym 0.0.53

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

okcomputerfan
mbakgun
.