PT-2026-99483 · Heym · Heym

CVE-2026-100863

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Heym versions prior to 0.0.91
Description Two server-side request forgery (SSRF) gaps exist in the software. First, the LLM image-edit input loader load image bytes() fetches HTTP/HTTPS URLs provided by the caller using a bare httpx.get, which only applies a scheme check and bypasses the egress-pinning HTTP client. This allows requests to target loopback, RFC1918, and cloud metadata endpoints when a workflow author uses the expression imageInput: $userInput.body.imageUrl. Second, the is public address() function only unwraps IPv4-mapped IPv6 addresses. Consequently, IPv6 transition forms—including the NAT64 well-known prefix 64:ff9b::/96, deprecated IPv4-compatible ::x.x.x.x addresses, and 6to4 (2002::/16)—can bypass initial URL validation and dial-time IP pinning to reach loopback, RFC1918, link-local, or cloud-metadata IPv4 destinations.
Recommendations Update Heym to version 0.0.91.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100863
GHSA-6RPH-QQCV-JQH4

Affected Products

Heym