Server-Side Request Forgery Vulnerability in Heym WebSocket Service
CVE-2026-84207

5.3MEDIUM

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84207?

Heym versions prior to 0.0.98 exhibit a vulnerability that allows authenticated users to exploit a Server-Side Request Forgery (SSRF) weakness. The flaw occurs due to the absence of egress guards when utilizing WebSocket Send and WebSocket Trigger nodes. By crafting workflow nodes with arbitrary URLs and custom headers, attackers can reach internal services, leading to potential unauthorized access and data exposure through the WebSocket Trigger node. Users are advised to upgrade to Heym version 0.0.98 or later to remediate this security issue.

Affected Version(s)

heym 0 < 0.0.98

heym 0.0.98

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

euriconicacio
.