PT-2026-99478 · Heym · Heym
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
heym versions prior to 0.0.109
Description
A server-side request forgery (SSRF) issue exists in the Slack, Discord, and Crawler workflow nodes. These nodes use an unguarded HTTP client to send requests to URLs provided in user-created credentials via the
webhook url or flaresolverr url variables. This bypasses the existing SSRF egress guard used by other nodes. Because the credential API only verifies that the URL is not empty, a registered user can configure a credential to point to internal addresses. This allows the backend to access loopback, private, link-local, or cloud-metadata endpoints and return the complete response body in the node output, resulting in a non-blind SSRF.Recommendations
Update heym to version 0.0.109 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heym