Impact
Heym versions before 0.0.53 do not verify Slack request signatures when trigger nodes either lack credential identifiers or have empty signing secrets. This vulnerability allows a remote, unauthenticated attacker to fabricate Slack events and post them to known webhook URLs. The forged requests are accepted as authentic, causing the application to execute the associated workflow using the owner's credentials, which can lead to arbitrary code execution or data exfiltration.
Affected Systems
Designated affected product is Heym from vendor Heymrun, specifically all releases prior to version 0.0.53.
Risk and Exploitability
The CVSS score of 8.3 classifies this flaw as high severity, and the EPSS metric is currently unavailable, implying no known widespread exploitation yet. It is not listed in CISA KEV. Attack paths rely on sending crafted HTTP requests to the Slack webhook endpoint, requiring no prior authentication or privileged access. Once leveraged, the attacker gains control over workflows running under the legitimate owner's environment.
OpenCVE Enrichment