Sceawere
Vulnerability Detail
CVE-2026-100861UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
heym SSRF via Egress Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5
- Creation Date
- 1d ago
- Vendor
- heymrun
- Product
- heym
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.0",
"pubDate": "2026-09-27T02:17:25.820Z",
"pubdate": "2026-09-27T02:17:25.820Z",
"executiveSummary": "The vulnerability identified in heym versions prior to 0.0.105 constitutes a Server-Side Request Forgery (SSRF) flaw stemming from the improper application of egress security controls. The defect resides in the integration services component, specifically where credential-supplied base URLs are utilized. Because these integration paths fail to enforce configured egress guards, the application allows authenticated users to bypass intended network restrictions.\nThe impact of this vulnerability is significant, as it enables an attacker to influence the server-side request target, directing it toward internal network resources, local loopback interfaces, or sensitive cloud-metadata services (e.g., 169.254.169.254). By manipulating the base URL within the credential configuration, an attacker can coerce the application into performing unauthorized requests on their behalf. The server then retrieves responses from these internal resources and returns them as workflow node output, effectively exfiltrating sensitive internal data or configuration details. Exploitation requires an authenticated user account with permissions to configure integration service credentials. This flaw presents a critical risk to internal network segmentation and cloud resource integrity.",
"technicalDetails": "The root cause of this SSRF vulnerability is a failure in the security middleware responsible for mediating outbound HTTP requests generated by integration services within heym. Specifically, when an integration utilizes a credential-supplied base URL, the internal egress guard logic is bypassed, failing to validate the destination against a blacklist or whitelist of authorized network endpoints.\nThe exploitation flow begins with an authenticated attacker gaining access to the integration service configuration module. Through the interface provided for setting up service credentials, the attacker defines a base URL pointing to prohibited network ranges, such as the local loopback address (127.0.0.1), private RFC1918 subnets, or cloud-specific instance metadata services. Because the egress guards are omitted for these specific credential-based requests, the application fails to perform the necessary DNS or IP-level resolution filtering.\nWhen a workflow node triggers an integration execution, the application initiates an outbound request using the attacker-supplied, malicious base URL. The underlying HTTP client performs the request to the restricted internal resource. The server then receives the response from the internal service—which may contain sensitive data such as system configuration, internal environment variables, or cloud provider identity tokens—and processes it within the context of the workflow engine. Finally, the server serializes this response data into the workflow node output, which is then accessible to the attacker through the standard UI or API response payload.\nThis vulnerability specifically affects all heym versions before 0.0.105. The lack of validation occurs within the integration service abstraction layer where credential handling logic overrides standard egress security policy enforcement. The exploit requires authentication, but given that many integration platforms allow users to define their own service configurations, this represents a significant escalation of privilege and a total compromise of the application's outbound request integrity.\nSuccessful exploitation allows for arbitrary reading of data from internal network segments that the application server can reach. Post-exploitation impact may include the unauthorized retrieval of internal service headers, administrative console data, or temporary cloud credentials that could lead to further compromise of the underlying infrastructure hosting the heym instance."
}