Junglewise Threat Intelligence

CVE-2026-84207: Heym SSRF bypass in WebSocket nodes

CVE-2026-84207 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Heym. Vendors: Heym.

Executive brief

Heym is an agentic workflow orchestration platform that allows users to build and deploy automated business processes. A vulnerability in versions before 0.0.98 fails to enforce network access controls on WebSocket Send and WebSocket Trigger workflow nodes, allowing authenticated users to craft malicious workflows that reach internal services and potentially exfiltrate sensitive data through WebSocket responses.

Technical details

This is a Server-Side Request Forgery (SSRF) vulnerability caused by insufficient egress validation on WebSocket workflow nodes. The vulnerable WebSocket Send and WebSocket Trigger nodes fail to apply security guards that restrict outbound connections to internal services. An authenticated attacker can craft workflow nodes with arbitrary URLs and custom headers to bypass network policy controls and connect to internal resources (databases, metadata services, internal APIs) that should be inaccessible. The WebSocket Trigger node can additionally read and exfiltrate response data. This vulnerability requires authentication and access to the workflow builder interface. The fix is available in version 0.0.98 and later.

Affected products

  • Heym Heym before 0.0.98

Timeline

  • 2026-09-01: disclosed

References