Token Leakage Vulnerability in Heym by Heymrun
CVE-2026-105396

5.3MEDIUM

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105396?

A token leakage vulnerability exists in Heym versions prior to v0.0.112 within the build_public_base_url() function. This flaw allows unauthorized attackers to manipulate the Origin or X-Forwarded-Host headers, enabling redirection of HITL review links. By exploiting this weakness, attackers can trigger anonymous workflows that divert reviewer notifications to malicious domains, thereby capturing sensitive capability tokens. These tokens can be misused to submit decisions under the guise of legitimate owner credentials, posing significant risks to system integrity and user data security.

Affected Version(s)

heym 0 < 0.0.112

heym 0.0.112

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xiaodu55
mbakgun
.