CVE-2026-100859 HIGH

CVE-2026-100859: Heym before 0.0.106 Credential Exfiltration via URL Override

Vendor Heymrun
Product heym
Weakness CWE-918 · SSRF
Published September 27, 2026
Last update September 27, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints.

Key dates

02Disclosure timeline

September 27, 2026 CVE published

Related vulnerabilities

04Related CVE