Impact
Heym before 0.0.53 fails to validate the X‑Telegram‑Bot‑Api‑Secret‑Token header on webhook endpoints when credential_id is missing or secret_token is empty. An attacker can send forged Telegram updates that bypass authentication, causing the application to execute workflows with the owner’s credentials and run attacker‑supplied actions.
Affected Systems
Vendors: heymrun’s Heym application. All releases prior to version 0.0.53 are affected. No further patch or version information is provided beyond the stated cutoff.
Risk and Exploitability
With a CVSS score of 8.3, this flaw poses high severity. While no EPSS score is reported and it is not currently listed in CISA KEV, the vulnerability can be exploited remotely over the internet via the Telegram webhook interface. Attackers who can reach the webhook endpoint can trigger arbitrary actions without authentication, potentially compromising the system’s integrity and confidentiality.
OpenCVE Enrichment