Description
Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured credentials and execute actions on attacker-supplied input.
Published: 2026-09-27
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Remote code execution via unauthorized workflow triggers
Action: Immediate Patch
AI Analysis

Impact

Heym before 0.0.53 fails to validate the X‑Telegram‑Bot‑Api‑Secret‑Token header on webhook endpoints when credential_id is missing or secret_token is empty. An attacker can send forged Telegram updates that bypass authentication, causing the application to execute workflows with the owner’s credentials and run attacker‑supplied actions.

Affected Systems

Vendors: heymrun’s Heym application. All releases prior to version 0.0.53 are affected. No further patch or version information is provided beyond the stated cutoff.

Risk and Exploitability

With a CVSS score of 8.3, this flaw poses high severity. While no EPSS score is reported and it is not currently listed in CISA KEV, the vulnerability can be exploited remotely over the internet via the Telegram webhook interface. Attackers who can reach the webhook endpoint can trigger arbitrary actions without authentication, potentially compromising the system’s integrity and confidentiality.

Generated by OpenCVE AI on September 27, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Heym 0.0.53 or later to receive the authentication check fix.
  • If upgrading is not immediately possible, restrict access to the webhook URL to the IP addresses of your trusted network or implement an additional shared secret that validates incoming requests.
  • Rotate any bot or workflow credentials that may have been exposed through forged updates and audit workflow logs for abnormal activity.

Generated by OpenCVE AI on September 27, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured credentials and execute actions on attacker-supplied input.
Title Heym before 0.0.53 Authentication Bypass via Telegram Webhook
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T16:33:43.037Z

Reserved: 2026-09-27T15:48:49.472Z

Link: CVE-2026-101050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:56.100

Modified: 2026-09-27T17:16:56.100

Link: CVE-2026-101050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:30:17Z

Weaknesses