Description
Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.
Published: 2026-09-27
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Heym versions before 0.0.53 do not verify Slack request signatures when trigger nodes either lack credential identifiers or have empty signing secrets. This vulnerability allows a remote, unauthenticated attacker to fabricate Slack events and post them to known webhook URLs. The forged requests are accepted as authentic, causing the application to execute the associated workflow using the owner's credentials, which can lead to arbitrary code execution or data exfiltration.

Affected Systems

Designated affected product is Heym from vendor Heymrun, specifically all releases prior to version 0.0.53.

Risk and Exploitability

The CVSS score of 8.3 classifies this flaw as high severity, and the EPSS metric is currently unavailable, implying no known widespread exploitation yet. It is not listed in CISA KEV. Attack paths rely on sending crafted HTTP requests to the Slack webhook endpoint, requiring no prior authentication or privileged access. Once leveraged, the attacker gains control over workflows running under the legitimate owner's environment.

Generated by OpenCVE AI on September 27, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Heym 0.0.53 update or a later version that fixes signature verification.
  • Disable or remove any trigger nodes that lack credential IDs or configure them with non‑empty signing secrets.
  • If the patch cannot be applied immediately, enforce network‑level filtering to block or validate Slack IP ranges or implement additional verification before accepting webhook events.

Generated by OpenCVE AI on September 27, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Heymrun
Heymrun heym
Vendors & Products Heymrun
Heymrun heym

Sun, 27 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.
Title Heym before 0.0.53 Slack Webhook Signature Verification Bypass
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T16:33:42.372Z

Reserved: 2026-09-27T15:48:49.472Z

Link: CVE-2026-101049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:55.967

Modified: 2026-09-27T17:16:55.967

Link: CVE-2026-101049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:45:12Z

Weaknesses