PT-2026-99557 · Heym · Heym
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Heym versions prior to 0.0.53
Description
Insufficient verification of the
X-Telegram-Bot-Api-Secret-Token header occurs on Telegram webhook endpoints when the credential id is absent or the secret token is empty. This allows remote unauthenticated attackers to send forged Telegram updates, triggering workflows using the owner's configured credentials to execute actions based on attacker-supplied input.Recommendations
Update to version 0.0.53 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heym