Description
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute those workflows under attacker-controlled execution paths, exposing victim workflow outputs and triggering workflow nodes with unintended side effects.
Published: 2026-05-12
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Heym before version 0.0.21 contains an authorization bypass that permits any authenticated user to trigger the execution of arbitrary workflows by referencing another user's workflow UUID. The flaw lies in the lack of proper access validation when resolving workflow identifiers for execute nodes or agent subWorkflowIds. When exploited, an attacker can craft workflows that load and run victim workflows under attacker‑controlled execution paths, thereby exposing victim outputs and potentially invoking side‑effecting nodes. This grants the attacker the ability to execute arbitrary actions defined in the victim's workflow, effectively bypassing intended isolation and confidentiality controls.

Affected Systems

The vulnerability affects the Heym platform, specifically all releases prior to 0.0.21. Users running any version below 0.0.21 should consider themselves potentially impacted. The vendor’s changelog indicates that version 0.0.21 includes the remediation for this issue.

Risk and Exploitability

The CVSS score of 7.6 classifies it as High severity. No EPSS score is available and it is not listed in CISA’s KEV catalog, suggesting no widespread exploit activity has been observed yet. The attack vector is likely local or network-based, requiring an attacker to first authenticate within the Heym system. Once authenticated, the attacker can submit crafted workflow payloads and trigger the bypass, leading to unintended execution of arbitrary workflow logic.

Generated by OpenCVE AI on May 12, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Heym to version 0.0.21 or newer to obtain the vendor patch.
  • Restrict the ability to create or execute workflows to privileged accounts and verify that workflow configuration checks enforce proper access control.
  • Audit workflow execution logs for anomalous or unauthorized activity and remediate any violations promptly.

Generated by OpenCVE AI on May 12, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Heymrun
Heymrun heym
Vendors & Products Heymrun
Heymrun heym

Tue, 12 May 2026 22:00:00 +0000

Type Values Removed Values Added
Description Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute those workflows under attacker-controlled execution paths, exposing victim workflow outputs and triggering workflow nodes with unintended side effects.
Title Heym < 0.0.21 Authorization Bypass in Workflow Execution
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-13T15:37:08.709Z

Reserved: 2026-05-11T14:14:49.611Z

Link: CVE-2026-45226

cve-icon Vulnrichment

Updated: 2026-05-13T15:04:20.314Z

cve-icon NVD

Status : Deferred

Published: 2026-05-12T22:16:38.127

Modified: 2026-05-13T15:26:44.333

Link: CVE-2026-45226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:35:27Z

Weaknesses