PT-2026-99556 · Heym · Heym
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Heym versions prior to 0.0.53
Description
The software fails to verify Slack request signatures in cases where trigger nodes are missing credential IDs or contain empty signing secrets. This allows remote unauthenticated attackers to send forged Slack events to known webhook URLs, which can trigger workflows using the credentials of the owner.
Recommendations
Update to version 0.0.53 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heym