Executive brief
Heym, an open-source tool, contains a security flaw in how it handles file uploads. An authenticated user can bypass intended storage limits to write, read, or delete files anywhere on the server's filesystem. This could allow an attacker to corrupt application data, overwrite critical system files, or potentially gain further control over the server.
Technical details
A path traversal vulnerability exists in Heym's file upload mechanism due to insufficient validation of the 'filename' parameter in the multipart upload flow. The 'upload_file()' handler in 'backend/app/api/files.py' passes the client-provided filename directly to storage helpers, which construct filesystem paths using simple string interpolation without normalization. By using traversal sequences (e.g., '../'), an authenticated attacker can escape the designated storage root to perform unauthorized file writes, reads, or deletions. The vulnerability is fixed in version 0.0.21 by implementing strict filename validation and resolved-path containment checks in the storage layer.
Affected products
- heymrun heym < 0.0.21
Timeline
- 2026-05-10: patched: Fix merged in PR #92 and released in v0.0.21
- 2026-05-12: advisory: VulnCheck advisory published
- 2026-05-12: disclosed: CVE-2026-45225 published