PT-2026-99484 · Heym · Heym
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
heym versions prior to 0.0.91
Description
A sandbox escape exists in the expression engine's DotList map/filter and fallback resolver. Authenticated users can execute arbitrary Python code by crafting workflow expressions that utilize dunder attribute access through item expressions or the fallback resolver to access
os.system and execute commands as the backend process.Recommendations
Update heym to version 0.0.91 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heym