PT-2026-99482 · Heym · Heym
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
heym versions prior to 0.0.91
Description
This workflow automation platform stores and returns multiple capability secrets in plaintext. Affected secrets include webhook header-auth values, which are returned in cleartext by the 'GET /api/workflows/{id}' endpoint and persisted unsanitized into execution history. MCP API keys are stored in a plaintext column, returned in config/list responses, and accepted via the
key query string, leading to leaks in logs, proxies, and Referer headers. Additionally, portal session tokens are stored and validated using plaintext equality with a 168-hour Time To Live (TTL), and workflow execution JSON Web Tokens (JWTs) are stored in full and re-listed by the 'GET .../execution-tokens' endpoint. Discord interaction tokens are also stored in full within the execution history, along with global variables. Users with read access to a workflow, share/team membership, or anyone with access to the database, backups, or logs can recover these secrets to execute workflows or impersonate the secret owner.Recommendations
Update heym to version 0.0.91 or later.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heym