CyberRota Analysis
AI-GeneratedHeym versions prior to 0.0.53 are vulnerable to multiple critical issues, including the use of Python eval() without proper sandboxing, which allows arbitrary code execution by users with workflow editing rights. Additionally, insufficient verification of webhook signatures and OAuth redirect URIs can lead to unauthorized access and execution of workflows, while sensitive tokens stored in plaintext pose a risk of exposure during database breaches. Organizations using Heym should prioritize patching to mitigate these high-severity vulnerabilities and protect their systems from potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.