PT-2026-99482 · Heym · Heym

·

CVE-2026-100862

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions heym versions prior to 0.0.91
Description This workflow automation platform stores and returns multiple capability secrets in plaintext. Affected secrets include webhook header-auth values, which are returned in cleartext by the 'GET /api/workflows/{id}' endpoint and persisted unsanitized into execution history. MCP API keys are stored in a plaintext column, returned in config/list responses, and accepted via the key query string, leading to leaks in logs, proxies, and Referer headers. Additionally, portal session tokens are stored and validated using plaintext equality with a 168-hour Time To Live (TTL), and workflow execution JSON Web Tokens (JWTs) are stored in full and re-listed by the 'GET .../execution-tokens' endpoint. Discord interaction tokens are also stored in full within the execution history, along with global variables. Users with read access to a workflow, share/team membership, or anyone with access to the database, backups, or logs can recover these secrets to execute workflows or impersonate the secret owner.
Recommendations Update heym to version 0.0.91 or later.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100862
GHSA-6X65-W7Q7-WG93

Affected Products

Heym