CVE-2026-105396 PUBLISHED

Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header

Assigner: VulnCheck
Reserved: 05.10.2026 Published: 05.10.2026 Updated: 05.10.2026

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor heymrun
Product heym
Versions Default: unaffected
  • affected from 0 to 0.0.112 (excl.)
  • Version 0.0.112 is unaffected

Credits

  • xiaodu55 reporter
  • mbakgun finder

References

Problem Types

  • Origin Validation Error CWE