Impact
The flaw allows authenticated users to supply credentials that point to loopback, private, or cloud‑metadata addresses and bypass egress guards applied to integration services. This permits the application to issue HTTP requests to internal services and return the responses as part of workflow node output, exposing sensitive internal data. The vulnerability is an SSRF that can be used to read or manipulate internal resources within the host environment.
Affected Systems
The issue affects the heym application from heymrun prior to version 0.0.105. Any installation that has not yet upgraded to the fixed release is potentially susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity condition. Unsurprisingly there is no EPSS data available and the weakness is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. Because the attack requires an authenticated account with the ability to configure integration credentials, the exploitability is constrained to users that have sufficient permissions within the application.
OpenCVE Enrichment