CVE-2026-100861: heym before 0.0.105 SSRF via credential-controlled base URLs
heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
heymto a version that resolves this vulnerability.Fixed in 0.0.105
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who can configure integration credentials with a base URL can exploit it. The attacker can point that URL at loopback, private-network, or cloud-metadata addresses.
What can an attacker obtain through exploitation?
The issue allows the attacker to read responses from internal services. Those responses are returned as workflow node output.
Are all Heym versions affected?
The issue affects Heym versions before 0.0.105. Version 0.0.105 is not identified as affected in the provided data.