CVE-2026-101049: Heym before 0.0.53 Slack Webhook Signature Verification Bypass
Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Heym versions before 0.0.53 are affected where Slack trigger nodes lack credential IDs or use an empty signing secret. An attacker also needs to know the relevant Slack webhook URL.
What does an attacker need to exploit this?
The attacker does not need authentication or user interaction. They must be able to send forged Slack events to a known webhook URL and exploit a trigger node with no credential ID or an empty signing secret.
What is the impact of a successful exploit?
Forged Slack events can trigger workflows using the workflow owner's credentials. This can lead to unauthorized actions and integrity impact through those workflows.
What should be prioritized if immediate upgrading is not possible?
Identify Slack trigger nodes without credential IDs or with empty signing secrets, and ensure they are configured with valid credentials and non-empty signing secrets. Restrict exposure of webhook URLs where possible, since knowledge of the URL is needed to send forged events.