Sceawere
Vulnerability Detail
CVE-2026-100858UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
heym SSRF via Workflow Nodes
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 1d ago
- Vendor
- heymrun
- Product
- heym
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP nodes; the credential API validates only that the URL is non-empty. Any registered user can create a credential pointing at an internal address and execute a workflow, causing the backend to reach loopback, private, link-local, or cloud-metadata endpoints and return the full response body in the node output (non-blind SSRF).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-09-27T02:17:25.340Z",
"pubdate": "2026-09-27T02:17:25.340Z",
"executiveSummary": "heym versions prior to 0.0.109 are susceptible to a critical Server-Side Request Forgery (SSRF) vulnerability. This flaw exists within the Slack, Discord, and Crawler workflow nodes, which utilize an inadequately secured HTTP client for external requests. Unlike other workflow components, these specific nodes bypass existing server-side egress filtering mechanisms designed to prevent unauthorized access to sensitive internal resources.\nThe vulnerability allows any authenticated user to supply arbitrary URLs through webhook_url or flaresolverr_url credentials. Because the credential API performs only basic non-empty validation, an attacker can coerce the backend server to perform requests against loopback addresses, private network ranges, link-local segments, and cloud provider metadata services. This enables non-blind SSRF, where the backend returns the complete response body directly to the node output, potentially exposing sensitive environment variables, internal configuration data, or private service interactions. The risk level is elevated due to the ease of exploitation, requiring only standard user-level access to execute a workflow and trigger the underlying HTTP request.",
"technicalDetails": "The root cause of this vulnerability is an inconsistent application of security controls across the heym workflow engine's infrastructure. While the HTTP, WebSocket, and MCP nodes implement mandatory SSRF egress guards, the Slack, Discord, and Crawler nodes utilize a decoupled HTTP client that lacks these ingress-egress validation hooks.\nDuring the credential creation process, the application validates input only for presence (ensuring the URL field is non-empty) but fails to perform structural validation, allowlist filtering, or network-level boundary enforcement. Consequently, the application does not inspect the target host against known internal CIDR blocks or restricted interfaces such as 127.0.0.1, 169.254.169.254, or internal RFC1918 address spaces.\nThe attack flow proceeds as follows: First, an authenticated user creates a malicious credential object, populating the webhook_url or flaresolverr_url field with a crafted target internal endpoint. Second, the user configures a workflow utilizing the vulnerable Slack, Discord, or Crawler node, referencing the compromised credential. Third, upon workflow execution, the backend system initiates an HTTP request using the untrusted, unvalidated URL provided in the credential. Fourth, because the HTTP client lacks egress filtering, the request traverses the backend's internal network stack. Finally, the backend captures the HTTP response from the targeted internal resource and routes it back to the node output, allowing the attacker to exfiltrate data from restricted services.\nThis is classified as a non-blind SSRF, as the node returns the full response body to the end-user. This allows for the exfiltration of sensitive information, such as cloud metadata tokens which can facilitate privilege escalation or lateral movement within a cloud environment. The vulnerability resides in the backend request handling logic for the specified nodes and affects all versions of heym prior to 0.0.109. No special privileges beyond standard user registration are required to trigger the vulnerability, and the exploitation is entirely successful within the context of standard application authentication."
}