Heym · Heym · CVE-2026-100861
**Name of the Vulnerable Software and Affected Versions**
heym versions prior to 0.0.105
**Description**
Authenticated users can bypass Server-Side Request Forgery (SSRF) protections—a flaw where an attacker induces a server to make requests to an unintended location—due to a failure in applying egress guards to integration services that utilize credential-supplied base URLs. This allows attackers to configure credentials pointing to loopback, private, or cloud-metadata addresses to read internal service responses returned as workflow node output.
**Recommendations**
Update to version 0.0.105 or later.