Junglewise Threat Intelligence

CVE-2026-100862: heym workflow automation multiple secrets plaintext storage

CVE-2026-100862 · Severity: medium · CVSS 4.9 · Published 2026-09-27

Technologies: Heym. Vendors: Heym.

Executive brief

heym is a workflow automation platform that allows users to orchestrate tasks and integrations. The platform stores multiple types of capability secrets—including webhook authentication headers, API keys, session tokens, and integration tokens—in plaintext rather than encrypted, allowing anyone with database access, backups, logs, or low-privilege workspace membership to recover and replay these secrets to execute workflows or impersonate legitimate users.

Technical details

Six distinct secret-handling gaps allow plaintext recovery: webhook auth headers are returned in API responses and persisted unsanitized to execution history; MCP API keys are stored and returned in plaintext, accepted via query strings (leaking to logs and proxies); portal session tokens are stored and validated by plaintext equality; workflow execution JWTs are stored in full and re-listed; Discord interaction tokens are persisted in execution history; and global variables are stored unencrypted and fully readable by team members. An attacker with database read access, backup access, log access, or workflow/team membership can extract these secrets and use them to execute workflows as the legitimate owner.

Affected products

  • heym heym prior to 0.0.91

Timeline

  • 2026-08-15: disclosed: GitHub security advisory GHSA-6x65-w7q7-wg93 published
  • 2026-09-27: patched: Fix released in version 0.0.91
  • 2026-09-27: advisory: NVD entry published as CVE-2026-100862

References

Related threats