CVE-2026-105396: Heymrun Heym

Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.

Affected products

  • Heymrun Heym: before 0.0.112 (fixed in 0.0.112)

Published 2026-10-05. Last modified 2026-10-05.