Heym · Heym · CVE-2026-100862
**Name of the Vulnerable Software and Affected Versions**
heym versions prior to 0.0.91
**Description**
This workflow automation platform stores and returns multiple capability secrets in plaintext. Affected secrets include webhook header-auth values, which are returned in cleartext by the 'GET /api/workflows/{id}' endpoint and persisted unsanitized into execution history. MCP API keys are stored in a plaintext column, returned in config/list responses, and accepted via the `key` query string, leading to leaks in logs, proxies, and Referer headers. Additionally, portal session tokens are stored and validated using plaintext equality with a 168-hour Time To Live (TTL), and workflow execution JSON Web Tokens (JWTs) are stored in full and re-listed by the 'GET .../execution-tokens' endpoint. Discord interaction tokens are also stored in full within the execution history, along with global variables. Users with read access to a workflow, share/team membership, or anyone with access to the database, backups, or logs can recover these secrets to execute workflows or impersonate the secret owner.
**Recommendations**
Update heym to version 0.0.91 or later.