PT-2026-99479 · Heym · Heym

·

CVE-2026-100859

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Heym versions prior to 0.0.106
Description An issue exists in the 'POST /api/credentials/test' endpoint that allows collaborators with shared credential access to exfiltrate the secret of the credential owner. An attacker can override the destination URL using the config parameter, causing the server to send decrypted authentication secrets to an external endpoint controlled by the attacker.
Recommendations Update to version 0.0.106 or later. Avoid using the config parameter in the 'POST /api/credentials/test' endpoint until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100859
GHSA-39QX-WP7X-69RQ

Affected Products

Heym