Authentication Bypass Issue in Heym Product by Heymrun
CVE-2026-101050
8.3HIGH
What is CVE-2026-101050?
The Heym product prior to version 0.0.53 has a significant flaw in how it handles the X-Telegram-Bot-Api-Secret-Token header in its webhook endpoints. When the credential_id is missing or the secret_token is left empty, this creates an opportunity for remote unauthenticated attackers to send forged Telegram updates. This vulnerability allows attackers to exploit workflows configured by the owner, potentially leading to unauthorized actions executed using attacker-supplied input. It is crucial for users of the affected versions to apply the necessary updates to ensure the security of their applications.
Affected Version(s)
heym 0 < 0.0.53
heym 0.0.53
