CVE-2026-105396: Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header
Heym before v0.0.112 contains a token leakage vulnerability in buildpublicbaseurl() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Heym deployments running versions before v0.0.112 are affected if anonymous workflows can be triggered and HITL reviewer notifications are generated. Reviewers who follow redirected review links may expose capability tokens to an attacker-controlled domain.
What does an attacker need to exploit it?
The attacker does not need authentication. They need to trigger an anonymous workflow while supplying a forged Origin or X-Forwarded-Host header, causing the generated HITL review link to use an attacker-controlled domain.
What is the impact after a token is captured?
A captured capability token can be used to submit HITL decisions. Those decisions are executed with the owner's credentials, which can affect confidentiality and integrity.
How can this be mitigated if upgrading is not immediately possible?
The provided information identifies spoofable Origin and X-Forwarded-Host headers as the attack path. Restrict or sanitize these headers before they reach Heym, and prevent untrusted clients from triggering anonymous workflows that generate HITL review notifications.