OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100865

HIGH · CVSS 8.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Heym versions prior to 0.0.53 are vulnerable to multiple critical issues, including the use of Python eval() without proper sandboxing, which allows arbitrary code execution by users with workflow editing rights. Additionally, insufficient verification of webhook signatures and OAuth redirect URIs can lead to unauthorized access and execution of workflows, while sensitive tokens stored in plaintext pose a risk of exposure during database breaches. Organizations using Heym should prioritize patching to mitigate these high-severity vulnerabilities and protect their systems from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100865
Severity
HIGH
CVSS
8.8
EPSS
0.32%

Original NVD Description

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.