Webhook Signature Verification Bypass in Heym by Heymrun
CVE-2026-101049
8.3HIGH
What is CVE-2026-101049?
The Heym application prior to version 0.0.53 is susceptible to a significant security flaw that enables remote attackers to bypass Slack request signature verification. This vulnerability arises when trigger nodes lack credential IDs or contain empty signing secrets, allowing malicious users to send fraudulent Slack events to known webhook URLs. As a result, attackers can initiate workflows as if they were the legitimate owner, potentially leading to unauthorized access and actions within the system.
Affected Version(s)
heym 0 < 0.0.53
heym 0.0.53
