๐Ÿ” CVE Alert

CVE-2026-105396

MEDIUM 5.4

Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.

CWE CWE-346
Vendor heymrun
Product heym
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for heymrun heym

Be the first to know when new medium vulnerabilities affecting heymrun heym are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

heymrun / heym
0 < 0.0.112

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/heymrun/heym/security/advisories/GHSA-6rv3-wh25-7pg5 vulncheck.com: https://www.vulncheck.com/advisories/heym-before-0.0.112-hitl-review-token-leak-via-spoofable-origin-header

Credits

๐Ÿ” xiaodu55 mbakgun