Junglewise Threat Intelligence

CVE-2026-100860: heym Redis node credential authorization bypass

CVE-2026-100860 · Severity: medium · CVSS 5.5 · Published 2026-09-27

Technologies: Heym. Vendors: Heym.

Executive brief

heym is a workflow automation platform that lets users build and execute workflows with various integrations. When an authenticated workflow author references a Redis credential they don't own or that has been deleted, the system falls back to connecting to the local Redis instance on localhost:6379 with no password, bypassing authorization checks. On deployments with an accessible local Redis, this allows unauthorized read/write access to that Redis instance.

Technical details

The Redis workflow node fails to check the result of _get_accessible_credential(), which returns None on authorization failure or missing credentials. This None is treated as an empty configuration, causing all connection parameters to default to localhost:6379 with no password. An authenticated attacker supplies a credential ID they don't own to trigger this fallback, gaining unauthorized access to any Redis service listening on the backend's loopback interface.

Affected products

  • heym heym before 0.0.105

Timeline

  • 2026-09-27: disclosed: CVE-2026-100860 published
  • 2026-09-03: patched: v0.0.105 released with fix
  • 2026-09-03: advisory: GHSA-fmpw-hj3m-xvj6 published

References

Related threats