Heym 0.0.90 及更早版本中存在两个服务器端请求伪造(SSRF)出口控制缺陷,这两个漏洞均已在 0.0.91 版本的 app/services/ssrf_guard.py 中得到修复。 首先,LLM 图像编辑输入加载器(_load_image_bytes)使用未经充分保护的 httpx.get 获取由调用者控制的 HTTP/HTTPS URL,仅进行了协议方案(scheme)检查,而未使用具备出口限制功能的 HTTP 客户端。由于工作流 DSL(领域特定语言)支持 “imageInput”: “$userI
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100864 | 8.8 HIGH | heym before 0.0.91 Remote Code Execution via Expression Engine |
| CVE-2026-100865 | 8.8 HIGH | Heym before 0.0.53 Remote Code Execution via eval() Sandbox Escape |
| CVE-2026-100858 | 6.8 MEDIUM | heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes |
| CVE-2026-101050 | 6.5 MEDIUM | Heym before 0.0.53 Authentication Bypass via Telegram Webhook |
| CVE-2026-101049 | 6.5 MEDIUM | Heym before 0.0.53 Slack Webhook Signature Verification Bypass |
| CVE-2026-100859 | 6.5 MEDIUM | Heym before 0.0.106 Credential Exfiltration via URL Override |
| CVE-2026-100860 | 5.5 MEDIUM | heym before 0.0.105 Authentication Bypass via Redis Node |
| CVE-2026-100861 | 5.0 MEDIUM | heym before 0.0.105 SSRF via credential-controlled base URLs |
| CVE-2026-100862 | 4.9 MEDIUM | heym before 0.0.91 Multiple Secrets Plaintext Storage |
No comments yet