Description
Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated token leakage enabling unauthorized workflow execution
Action: Patch immediately
AI Analysis

Impact

Heym before version 0.0.112 contains a token leakage flaw in the build_public_base_url() function. An attacker can supply forged Origin or X‑Forwarded‑Host headers to redirect Hit‑the‑line review links. The redirect causes reviewer notifications to point to attacker‑controlled domains, where the attacker captures capability tokens that allow submitting decisions with the owner’s credentials. This flaw permits an unauthenticated attacker to gain authorization to execute actions that normally require explicit approval.

Affected Systems

The vulnerability affects the Heym application provided by heymrun, specifically all releases prior to 0.0.112. No precise sub‑version range is listed beyond the pre‑0.0.112 barrier; administrators using older versions should verify the release number.

Risk and Exploitability

The CVSS score is 5.3, reflecting moderate impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale exploitation campaigns have been documented yet. The attack requires an external attacker to send HTTP requests with spoofed Origin or X‑Forwarded‑Host headers, a scenario that is feasible in open or public environments but does not require privileged access.

Generated by OpenCVE AI on October 5, 2026 at 12:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Heym to version 0.0.112 or later to eliminate the build_public_base_url() token leakage.
  • If an upgrade is not possible, configure the reverse proxy or application firewall to reject or ignore spoofed Origin or X‑Forwarded‑Host headers for Hit‑the‑line review traffic.
  • After mitigation, audit or rotate any capability tokens that may have been exposed through email notifications to prevent retained abuse.

Generated by OpenCVE AI on October 5, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Heymrun
Heymrun heym
Vendors & Products Heymrun
Heymrun heym

Mon, 05 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
Title Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T11:09:45.174Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T12:17:09.583

Modified: 2026-10-05T12:17:09.583

Link: CVE-2026-105396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T13:00:16Z

Weaknesses