No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Heymrun
Heymrun heym |
|
| Vendors & Products |
Heymrun
Heymrun heym |
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persisted unsanitized into execution history), MCP API keys (stored as a plaintext column, returned in config/list responses, and accepted via the ?key= query string so they leak into logs, proxies and Referer headers), portal session tokens (stored and validated by plaintext equality with a 168-hour TTL), workflow execution JWTs (stored in full and re-listed by GET .../execution-tokens), Discord interaction tokens (the full interaction body is stored in execution history), and global variables. A user with read access to a workflow, share/team membership, or anyone able to read the database, a backup, or logs can recover these secrets and replay them to execute workflows or act as the secret owner. | |
| Title | heym before 0.0.91 Multiple Secrets Plaintext Storage | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T01:28:51.915Z
Reserved: 2026-09-27T00:20:03.854Z
Link: CVE-2026-100862
No data.
Status : Received
Published: 2026-09-27T02:17:25.963
Modified: 2026-09-27T02:17:25.963
Link: CVE-2026-100862
No data.
OpenCVE Enrichment
Updated: 2026-09-27T04:45:17Z
-
CWE-312
Cleartext Storage of Sensitive Information