Executive brief
Heym is an AI agent workflow platform that allows users to run custom Python code as part of their automation. A security flaw in the code execution environment allows an authorized user to break out of the restricted 'sandbox' and run unauthorized commands on the underlying server. This could lead to the theft of sensitive database credentials, encryption keys, and full control over the backend service.
Technical details
A sandbox escape exists in the `python_tool_executor.py` component of Heym due to insufficient filtering of Python introspection primitives. While the environment attempted to blacklist dangerous builtins like `exec` and `__import__`, an attacker can use object-graph introspection (e.g., accessing `__subclasses__` via the `object` class) to recover the original `__builtins__` dictionary. This allows the importation of restricted modules such as `os` and `subprocess`. Furthermore, because the tool runner inherited the backend's environment variables and working directory, an attacker can extract sensitive secrets or execute commands as the backend service user. The vulnerability is fixed in version 0.0.21 by implementing AST-based validation and scrubbing the subprocess environment.
Affected products
- heymrun Heym < 0.0.21
Timeline
- 2026-05-10: patched: Fix merged in PR #94 and released in v0.0.21
- 2026-05-12: advisory: NVD and VulnCheck advisory published