PT-2026-99481 · Heym · Heym

·

CVE-2026-100861

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions heym versions prior to 0.0.105
Description Authenticated users can bypass Server-Side Request Forgery (SSRF) protections—a flaw where an attacker induces a server to make requests to an unintended location—due to a failure in applying egress guards to integration services that utilize credential-supplied base URLs. This allows attackers to configure credentials pointing to loopback, private, or cloud-metadata addresses to read internal service responses returned as workflow node output.
Recommendations Update to version 0.0.105 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100861
GHSA-XCHJ-MW74-2232

Affected Products

Heym