Impact
Heym before version 0.0.112 contains a token leakage flaw in the build_public_base_url() function. An attacker can supply forged Origin or X‑Forwarded‑Host headers to redirect Hit‑the‑line review links. The redirect causes reviewer notifications to point to attacker‑controlled domains, where the attacker captures capability tokens that allow submitting decisions with the owner’s credentials. This flaw permits an unauthenticated attacker to gain authorization to execute actions that normally require explicit approval.
Affected Systems
The vulnerability affects the Heym application provided by heymrun, specifically all releases prior to 0.0.112. No precise sub‑version range is listed beyond the pre‑0.0.112 barrier; administrators using older versions should verify the release number.
Risk and Exploitability
The CVSS score is 5.3, reflecting moderate impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale exploitation campaigns have been documented yet. The attack requires an external attacker to send HTTP requests with spoofed Origin or X‑Forwarded‑Host headers, a scenario that is feasible in open or public environments but does not require privileged access.
OpenCVE Enrichment