PT-2026-84305 · Heym · Heym

·

CVE-2026-84207

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Heym versions prior to 0.0.98
Description Authenticated users can connect to internal services because the software fails to apply Server-Side Request Forgery (SSRF) egress guards to the WebSocket Send and WebSocket Trigger nodes. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. Attackers can create workflow nodes with arbitrary URLs and headers to access internal services and read responses from the WebSocket Trigger node.
Recommendations Update to version 0.0.98 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84207
GHSA-MQW6-G845-W596

Affected Products

Heym