heym 0.0.109 之前版本中的 Slack、Discord 和 Crawler 工作流节点存在服务端请求伪造(SSRF)漏洞。这些节点使用未加防护的 HTTP 客户端,向用户凭据(webhook_url / flaresolverr_url)中指定的 URL 发起 HTTP 请求,从而绕过了已用于保护 HTTP、WebSocket 和 MCP 节点的 SSRF 出口防护机制;而凭据 API 仅校验 URL 非空,未对其内容进行任何限制。任何已注册用户均可创建指向内部地址的凭据并执行工作流,导致后端访问回环地
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100864 | 8.8 HIGH | heym before 0.0.91 Remote Code Execution via Expression Engine |
| CVE-2026-100865 | 8.8 HIGH | Heym before 0.0.53 Remote Code Execution via eval() Sandbox Escape |
| CVE-2026-101050 | 6.5 MEDIUM | Heym before 0.0.53 Authentication Bypass via Telegram Webhook |
| CVE-2026-101049 | 6.5 MEDIUM | Heym before 0.0.53 Slack Webhook Signature Verification Bypass |
| CVE-2026-100859 | 6.5 MEDIUM | Heym before 0.0.106 Credential Exfiltration via URL Override |
| CVE-2026-100860 | 5.5 MEDIUM | heym before 0.0.105 Authentication Bypass via Redis Node |
| CVE-2026-100861 | 5.0 MEDIUM | heym before 0.0.105 SSRF via credential-controlled base URLs |
| CVE-2026-100863 | 5.0 MEDIUM | Heym before 0.0.91 SSRF via image fetching and IPv6 validation |
| CVE-2026-100862 | 4.9 MEDIUM | heym before 0.0.91 Multiple Secrets Plaintext Storage |
No comments yet