CVE-2026-105396: Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header

Published Oct 5, 2026
·
Updated

Heym before v0.0.112 contains a token leakage vulnerability in buildpublicbaseurl() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.

Affected Software

1 affected component
Heym Heym<0.0.112

Event History

Oct 5, 2026
CVE Published
via MITRE·11:09 AM
Data Sourced
via MITRE·11:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Heym deployments running versions before v0.0.112 are affected if anonymous workflows can be triggered and HITL reviewer notifications are generated. Reviewers who follow redirected review links may expose capability tokens to an attacker-controlled domain.

2

What does an attacker need to exploit it?

The attacker does not need authentication. They need to trigger an anonymous workflow while supplying a forged Origin or X-Forwarded-Host header, causing the generated HITL review link to use an attacker-controlled domain.

3

What is the impact after a token is captured?

A captured capability token can be used to submit HITL decisions. Those decisions are executed with the owner's credentials, which can affect confidentiality and integrity.

4

How can this be mitigated if upgrading is not immediately possible?

The provided information identifies spoofable Origin and X-Forwarded-Host headers as the attack path. Restrict or sanitize these headers before they reach Heym, and prevent untrusted clients from triggering anonymous workflows that generate HITL review notifications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203