Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100862— heym before 0.0.91 Multiple Secrets Plaintext Storage

Quick assessment

Affected
heymrun heym
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

嘿,一个工作流自动化平台在 0.0.91 版本之前会将多个能力密钥以明文形式存储和返回。受影响的密钥包括 webhook 头认证值(通过 GET /api/workflows/{id} 以明文形式返回,并以未清理的方式持久化到执行历史中)、MCP API 密钥(以明文列存储、在 config/list 响应中返回,并通过 ?key= 查询字符串接受,从而泄露到日志、代理和 Referer 头中)、门户会话令牌(以明文相等性存储和验证,TTL 为 168 小时)、工作流执行 JWT(完整存储并通过 GET .../e

CVSS 4.9 · Medium EPSS 0.19% · P8
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100862

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
heym before 0.0.91 Multiple Secrets Plaintext Storage
Source: CVE Program / CVE List V5
Vulnerability Description
heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persisted unsanitized into execution history), MCP API keys (stored as a plaintext column, returned in config/list responses, and accepted via the ?key= query string so they leak into logs, proxies and Referer headers), portal session tokens (stored and validated by plaintext equality with a 168-hour TTL), workflow execution JWTs (stored in full and re-listed by GET .../execution-tokens), Discord interaction tokens (the full interaction body is stored in execution history), and global variables. A user with read access to a workflow, share/team membership, or anyone able to read the database, a backup, or logs can recover these secrets and replay them to execute workflows or act as the secret owner.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文存储
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
heymrun heym 0 ~ 0.0.91 -

II. Public POCs for CVE-2026-100862

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100862

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100862 (1)

Other References for CVE-2026-100862 (1)

Same Patch Batch · heymrun · 2026-09-27 · 10 CVEs total

CVE-2026-100864 8.8 HIGH heym before 0.0.91 Remote Code Execution via Expression Engine
CVE-2026-100865 8.8 HIGH Heym before 0.0.53 Remote Code Execution via eval() Sandbox Escape
CVE-2026-100858 6.8 MEDIUM heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes
CVE-2026-101050 6.5 MEDIUM Heym before 0.0.53 Authentication Bypass via Telegram Webhook
CVE-2026-101049 6.5 MEDIUM Heym before 0.0.53 Slack Webhook Signature Verification Bypass
CVE-2026-100859 6.5 MEDIUM Heym before 0.0.106 Credential Exfiltration via URL Override
CVE-2026-100860 5.5 MEDIUM heym before 0.0.105 Authentication Bypass via Redis Node
CVE-2026-100861 5.0 MEDIUM heym before 0.0.105 SSRF via credential-controlled base URLs
CVE-2026-100863 5.0 MEDIUM Heym before 0.0.91 SSRF via image fetching and IPv6 validation

IV. Related Vulnerabilities

V. Comments for CVE-2026-100862

No comments yet


Leave a comment