CVE-2026-100865: Heymrun Heym

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.

Affected products

  • Heymrun Heym: before 0.0.53 (fixed in 0.0.53)

Published 2026-09-27. Last modified 2026-09-28.