CVE-2026-100859: Heym before 0.0.106 Credential Exfiltration via URL Override

Published Sep 27, 2026
·
Updated

Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints.

Affected Software

1 affected component
Heym Heym<0.0.106

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Heym to a version that resolves this vulnerability.

    Fixed in 0.0.106

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be a collaborator with shared access to a credential. The issue is remotely reachable and does not require user interaction.

2

What access or conditions are required to exfiltrate a secret?

The attacker needs access to the POST /api/credentials/test endpoint for a shared credential and must be able to supply a config parameter that overrides the destination URL. This causes the server to send the decrypted authentication secret to an attacker-controlled endpoint.

3

Which versions are affected?

Heym versions before 0.0.106 are affected. Upgrading to 0.0.106 or later addresses the affected version range.

4

What can be done if an upgrade is not immediately possible?

Restrict shared credential access to trusted collaborators and prevent untrusted users from invoking the credential test endpoint. Review and limit configuration that permits destination URL overrides, where possible.

5

How can defenders look for possible exploitation?

Review requests to POST /api/credentials/test for config values containing unexpected or attacker-controlled destination URLs. Also investigate outbound requests from the Heym server to unrecognized endpoints made during credential testing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203