Junglewise Threat Intelligence

CVE-2026-12060: Hepta Platforms Heptabase exposed dangerous function in internal browser

CVE-2026-12060 · Severity: medium · CVSS 6.5 · Published 2026-06-12

Executive brief

Heptabase, a visual note-taking and knowledge management application, contains a security flaw that could allow an attacker to access a user's camera and microphone. By tricking a user into opening a malicious link within the app, an attacker can bypass standard permission prompts to spy on the victim. This poses a significant privacy risk to users who handle sensitive information or conduct private meetings within the platform.

Technical details

Heptabase versions prior to 1.90.2 are vulnerable to an 'Exposed Dangerous Method or Function' (CWE-749) flaw. The vulnerability exists because the application exposes internal functions that can be triggered by external web content loaded within the app's environment. An unauthenticated remote attacker can exploit this by using social engineering to convince a user to load a specially crafted malicious webpage inside the Heptabase application. Successful exploitation grants the attacker unauthorized access to the device's camera and microphone permissions without the user's explicit consent. The issue is resolved in version 1.90.2.

Affected products

  • Hepta Platforms Heptabase before 1.90.2

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-12: patched: Fixed in version 1.90.2

References

Related threats