Webhook Signature Verification Bypass in Heym by Heymrun
CVE-2026-101049

8.3HIGH

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101049?

The Heym application prior to version 0.0.53 is susceptible to a significant security flaw that enables remote attackers to bypass Slack request signature verification. This vulnerability arises when trigger nodes lack credential IDs or contain empty signing secrets, allowing malicious users to send fraudulent Slack events to known webhook URLs. As a result, attackers can initiate workflows as if they were the legitimate owner, potentially leading to unauthorized access and actions within the system.

Affected Version(s)

heym 0 < 0.0.53

heym 0.0.53

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

okcomputerfan
mbakgun
.