Impact
The vulnerability exists in the POST /api/credentials/test endpoint of Heym versions prior to 0.0.106 and allows a user with collaborator access who already can view credentials to cause the server to send decrypted authentication secrets to an arbitrary destination URL supplied in the config parameter. This defect is a form of credential exfiltration and is identified as CWE-918. The impact is the exposure of sensitive authentication secrets to an attacker-controlled endpoint, potentially compromising user accounts even though the overall system still remains operational for legitimate users.
Affected Systems
Heym runs in versions before 0.0.106 and is affected by this defect. No broader version metadata is provided, but any instance of Heym running a preβ0.0.106 build is vulnerable.
Risk and Exploitability
The CVSS score for this vulnerability is 7.1, indicating a high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must have valid collaborator privileges to use the affected endpoint, and must supply an overridden destination URL. Therefore the attack vector is internal through granted access; exploitation is straightforward for authorized collaborators but requires no additional environmental conditions. Given the high severity and the ease of exploitation, the risk to systems running vulnerable versions is significant.
OpenCVE Enrichment