Junglewise Threat Intelligence

CVE-2026-100864: heym expression engine sandbox escape in DotList and fallback resolver

CVE-2026-100864 · Severity: high · CVSS 8.8 · Published 2026-09-27

Technologies: Heym. Vendors: Heym.

Executive brief

heym is a workflow automation platform that lets users define and execute data processing workflows through an expression engine. A vulnerability in the expression engine allows authenticated users to bypass sandbox restrictions and execute arbitrary Python code on the backend server, potentially exposing databases, stored credentials, and internal network access. This could lead to complete system compromise for any organization using heym to run critical workflows.

Technical details

The vulnerability exists in two code paths that bypass simpleeval sandboxing: the DotList item expression evaluator (used by .map()/.filter()/distinctBy()) and the _resolve_simple_expression fallback handler. Both use raw getattr without dunder restrictions, allowing attackers to traverse __class__.__base__.__subclasses__ to access loaded classes and their __init__.__globals__ to reach os.system. The attack requires authentication to edit/execute workflows or access the /api/expressions/evaluate endpoint, and is demonstrated through a chain of three expressions that progressively gains code execution as the backend process.

Affected products

  • heym heym before 0.0.91

Timeline

  • 2026-08-15: disclosed: GitHub Security Advisory GHSA-87x2-9jwx-7gh4 published
  • 2026-09-27: advisory: CVE-2026-100864 published on NVD
  • 2026-09-27: patched: Fixed in version 0.0.91 with dunder filtering, fail-closed fallback, and regression tests

References

Related threats