CVE-2026-100858
Last modified
CVE-2026-100858 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP nodes; the credential API validates only that the URL is non-empty.
Description
heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP nodes; the credential API validates only that the URL is non-empty. Any registered user can create a credential pointing at an internal address and execute a workflow, causing the backend to reach loopback, private, link-local, or cloud-metadata endpoints and return the full response body in the node output (non-blind SSRF).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| heymrun | heym | < 0.0.109 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100858?
How severe is CVE-2026-100858?
How do I fix CVE-2026-100858?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100852AzuraCast through 0.23.x contains a command injection vulner…8.8
- CVE-2026-100853In AzuraCast before 0.23.8, the public On-Demand download en…5.9
- CVE-2026-100854AzuraCast before 0.23.6 lacks RequireInternalConnection midd…6.3
- CVE-2026-100855AzuraCast before 0.23.6 contains a missing permission check …6.5
- CVE-2026-100856AzuraCast before 0.23.6 contains a code injection vulnerabil…8.8
- CVE-2026-100857AzuraCast before 0.23.4 contains a code injection vulnerabil…8
- CVE-2026-100859Heym before 0.0.106 contains a credential exfiltration vulne…6.5
- CVE-2026-10086GitLab has remediated an issue in GitLab EE affecting all ve…5.4
- CVE-2026-100860heym before 0.0.105 does not act on the result of the creden…5.5
- CVE-2026-100861heym before 0.0.105 fails to apply egress guards to integrat…5
- CVE-2026-100862heym, a workflow automation platform, stores and returns mul…4.9
- CVE-2026-100863Heym versions 0.0.90 and earlier contain two server-side req…5
Are you affected by CVE-2026-100858?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
