PT-2026-99480 · Heym · Heym

·

CVE-2026-100860

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions heym versions prior to 0.0.105
Description The Redis workflow node in backend/app/services/node execution/nodes/redis node.py fails to properly handle the result of credential authorization lookups. When the get accessible credential() function returns None—occurring if the credential ID is missing or the user lacks authorization—or if the credential has an empty configuration or lacks a redis host value, the system defaults to connecting to localhost:6379 without a password. This allows an authenticated workflow author to obtain read/write access to any Redis instance listening on the backend loopback interface by providing a deleted or unauthorized credential ID.
Recommendations Update heym to version 0.0.105 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100860
GHSA-FMPW-HJ3M-XVJ6

Affected Products

Heym