Sceawere
Vulnerability Detail
CVE-2026-100859UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Heym Credential Exfiltration Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1d ago
- Vendor
- heymrun
- Product
- heym
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-27T02:17:25.503Z",
"pubdate": "2026-09-27T02:17:25.503Z",
"executiveSummary": "The vulnerability identified in Heym (versions prior to 0.0.106) is a server-side credential exfiltration flaw located within the POST /api/credentials/test endpoint.\nThis vulnerability allows an authenticated collaborator with access to shared credentials to intercept and exfiltrate the secret data belonging to the credential owner.\nBy manipulating the configuration parameters during the credential testing process, an attacker can force the application to dispatch decrypted secrets to an arbitrary, attacker-controlled destination.\nThe primary risk involves the unauthorized exposure of sensitive authentication material, potentially leading to widespread account takeovers or lateral movement within environments integrated with Heym.\nThe vulnerability assumes that the attacker already possesses collaborator-level access to shared credentials, effectively exploiting the trust model and insufficient server-side validation of testing configurations.\nSuccessful exploitation requires minimal effort from an attacker with existing shared access, making this a high-severity issue for organizations relying on Heym for credential management.",
"technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and server-side validation of the 'config' parameter passed to the POST /api/credentials/test endpoint. In Heym versions prior to 0.0.106, the endpoint processes this parameter to facilitate the testing of connectivity or integration status for stored credentials.\nThe application design fails to enforce strict, hardcoded destinations or allow-lists for the test functionality. Instead, the backend trusts the client-provided destination URL within the configuration object without verifying if the endpoint belongs to an authorized or expected service provider.\nThe attack flow proceeds as follows: First, the attacker identifies a credential object shared with them in the Heym environment. Second, the attacker initiates a request to the /api/credentials/test endpoint. During the construction of this request, the attacker modifies the 'config' parameter, specifically targeting the destination URL field, substituting the legitimate integration endpoint with a URI pointing to an attacker-controlled listener.\nUpon receiving the request, the Heym server proceeds to decrypt the sensitive credential material associated with the targeted object to perform the 'test.' Because the server logic trusts the user-provided destination URL, it encapsulates the decrypted secret into the payload and transmits an HTTP request to the attacker's server.\nThis behavior results in a direct leakage of plaintext authentication secrets. Because the secret is decrypted on the server side prior to the transmission, the attacker successfully bypasses security boundaries intended to keep secrets confidential even from collaborators.\nThe exploit is facilitated by the fact that the application does not implement adequate server-side controls to limit the scope of the connectivity tests. The lack of validation on the destination URL allows the backend process to become an unintended proxy for sensitive data exfiltration.\nImpact includes complete compromise of the affected credentials. Once the secret is exfiltrated, the attacker can impersonate the legitimate owner, gaining unauthorized access to the third-party services protected by those credentials, such as cloud providers, CI/CD pipelines, or database services. The post-exploitation scenario is limited only by the permissions associated with the exfiltrated credentials."
}