Token Leakage Vulnerability in Heym by Heymrun
CVE-2026-105396
5.3MEDIUM
What is CVE-2026-105396?
A token leakage vulnerability exists in Heym versions prior to v0.0.112 within the build_public_base_url() function. This flaw allows unauthorized attackers to manipulate the Origin or X-Forwarded-Host headers, enabling redirection of HITL review links. By exploiting this weakness, attackers can trigger anonymous workflows that divert reviewer notifications to malicious domains, thereby capturing sensitive capability tokens. These tokens can be misused to submit decisions under the guise of legitimate owner credentials, posing significant risks to system integrity and user data security.
Affected Version(s)
heym 0 < 0.0.112
heym 0.0.112
