Sceawere
Vulnerability Detail
CVE-2026-100862UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
heym Multiple Secret Exposure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.9
- Creation Date
- 1d ago
- Vendor
- heymrun
- Product
- heym
- Attack Type
- Cleartext Storage of Sensitive Information
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persisted unsanitized into execution history), MCP API keys (stored as a plaintext column, returned in config/list responses, and accepted via the ?key= query string so they leak into logs, proxies and Referer headers), portal session tokens (stored and validated by plaintext equality with a 168-hour TTL), workflow execution JWTs (stored in full and re-listed by GET .../execution-tokens), Discord interaction tokens (the full interaction body is stored in execution history), and global variables. A user with read access to a workflow, share/team membership, or anyone able to read the database, a backup, or logs can recover these secrets and replay them to execute workflows or act as the secret owner.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.9",
"pubDate": "2026-09-27T02:17:25.963Z",
"pubdate": "2026-09-27T02:17:25.963Z",
"executiveSummary": "heym versions prior to 0.0.91 are affected by a critical vulnerability involving the improper storage and handling of sensitive capability secrets. The platform fails to encrypt or mask sensitive data, resulting in the plaintext exposure of webhook authentication headers, MCP API keys, portal session tokens, workflow execution JWTs, and Discord interaction tokens.\nThis vulnerability stems from insecure design practices where sensitive credentials are persisted in database columns, logged in plaintext, and returned in cleartext via API responses. The impact is broad, as any user with read access to a workflow, team membership, or unauthorized access to system logs, backups, or the underlying database can recover these secrets.\nThe risk implication is severe, as the exposed secrets enable attackers to perform unauthorized actions, hijack sessions, or impersonate workflow owners. Exploitation requires no advanced skill set, only the ability to query affected API endpoints or access system diagnostic data, posing a significant risk to the integrity and confidentiality of automated workflows and integrated third-party services.",
"technicalDetails": "The vulnerability in heym exists due to a systemic failure to sanitize and secure sensitive information at rest and in transit. In affected versions (pre-0.0.91), critical authentication materials are handled as plaintext, creating multiple vectors for credential exfiltration.\nRoot causes include: 1) Storing MCP API keys and session tokens in plaintext database columns. 2) Including sensitive credentials, such as MCP API keys, in query strings (?key=), leading to leakage in HTTP Referer headers, proxy logs, and application server access logs. 3) Returning comprehensive secret objects via API endpoints such as GET /api/workflows/{id} and GET .../execution-tokens without filtering or masking. 4) Persisting unsanitized workflow execution history, which captures full Discord interaction bodies and header-auth values.\nThe attack flow generally follows these steps: An authenticated attacker with read access to a workflow or shared environment performs a standard GET request to API endpoints, such as /api/workflows/{id}. The application returns the complete JSON configuration, including plaintext webhook header-auth values and stored JWTs. Simultaneously, if an attacker can gain access to application logs, they can extract MCP API keys leaked via URL query parameters or session tokens that persist due to a 168-hour TTL and lack of hashing. Once obtained, these secrets are replayed by the attacker to authenticate as the workflow owner or to gain unauthorized access to connected third-party integrations.\nThe exposure of portal session tokens is particularly egregious due to the lack of cryptographic verification; the system validates these tokens via simple plaintext equality checks. This allows for trivial session hijacking if an attacker retrieves the token from log files or database dumps. The persistence of full Discord interaction bodies within execution history further compounds the risk, as it potentially exposes sensitive communications or triggers contained within those interactions. The lack of proper secret management—specifically the absence of encryption-at-rest and the inclusion of credentials in logs—facilitates wide-scale credential harvesting from database backups and secondary infrastructure components."
}