CVE-2026-100859 PUBLISHED

Heym before 0.0.106 Credential Exfiltration via URL Override

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 27.09.2026 Updated: 27.09.2026

Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor heymrun
Product heym
Versions Default: unaffected
  • affected from 0 to 0.0.106 (excl.)
  • Version 0.0.106 is unaffected

Credits

  • roonakyadav reporter
  • mbakgun finder

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE