PT-2026-99478 · Heym · Heym

·

CVE-2026-100858

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions heym versions prior to 0.0.109
Description A server-side request forgery (SSRF) issue exists in the Slack, Discord, and Crawler workflow nodes. These nodes use an unguarded HTTP client to send requests to URLs provided in user-created credentials via the webhook url or flaresolverr url variables. This bypasses the existing SSRF egress guard used by other nodes. Because the credential API only verifies that the URL is not empty, a registered user can configure a credential to point to internal addresses. This allows the backend to access loopback, private, link-local, or cloud-metadata endpoints and return the complete response body in the node output, resulting in a non-blind SSRF.
Recommendations Update heym to version 0.0.109 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100858
GHSA-39J3-6X3X-8RCR

Affected Products

Heym