Executive brief
heym is a workflow automation platform that allows users to create workflows with Slack, Discord, and web crawler nodes. A server-side request forgery vulnerability allows any registered user to make the backend reach internal network addresses and cloud metadata endpoints by crafting malicious credentials, potentially exposing sensitive configuration, API responses, and cloud metadata that could lead to further compromise.
Technical details
The Slack, Discord, and Crawler workflow nodes accept URLs from user-created credentials (webhook_url and flaresolverr_url) and issue HTTP requests via an unguarded HTTP client, bypassing the SSRF guard that protects other nodes. The vulnerability is non-blind SSRF: the full response body is returned in node output. Exploitation requires user registration and workflow execution permissions, with no additional complexity beyond crafting a credential pointing to loopback (127.0.0.1), private subnets, link-local addresses, or cloud metadata endpoints.
Affected products
- heymrun heym before 0.0.109
Timeline
- 2026-09-12: disclosed
- 2026-09-27: patched: version 0.0.109