Executive brief
heym is a workflow automation platform that allows users to orchestrate tasks and integrations. The platform stores multiple types of capability secrets—including webhook authentication headers, API keys, session tokens, and integration tokens—in plaintext rather than encrypted, allowing anyone with database access, backups, logs, or low-privilege workspace membership to recover and replay these secrets to execute workflows or impersonate legitimate users.
Technical details
Six distinct secret-handling gaps allow plaintext recovery: webhook auth headers are returned in API responses and persisted unsanitized to execution history; MCP API keys are stored and returned in plaintext, accepted via query strings (leaking to logs and proxies); portal session tokens are stored and validated by plaintext equality; workflow execution JWTs are stored in full and re-listed; Discord interaction tokens are persisted in execution history; and global variables are stored unencrypted and fully readable by team members. An attacker with database read access, backup access, log access, or workflow/team membership can extract these secrets and use them to execute workflows as the legitimate owner.
Affected products
- heym heym prior to 0.0.91
Timeline
- 2026-08-15: disclosed: GitHub security advisory GHSA-6x65-w7q7-wg93 published
- 2026-09-27: patched: Fix released in version 0.0.91
- 2026-09-27: advisory: NVD entry published as CVE-2026-100862