Sceawere
Vulnerability Detail
CVE-2026-100864UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
heym Sandbox Escape RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- heymrun
- Product
- heym
- Attack Type
- Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fallback resolver to access os.system and execute commands as the backend process.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-27T02:17:26.260Z",
"pubdate": "2026-09-27T02:17:26.260Z",
"executiveSummary": "The heym package, specifically versions prior to 0.0.91, is susceptible to a critical sandbox escape vulnerability within its expression engine. This vulnerability stems from insecure implementations in the DotList map/filter functionality and the fallback resolver, which fail to properly restrict access to restricted Python attributes.\nBy leveraging dunder (double underscore) attribute access, an authenticated attacker can bypass intended sandbox restrictions to reach underlying sensitive Python modules, such as the os module. This allows for arbitrary code execution with the privileges of the backend process executing the workflow expressions.\nThe risk is severe, as successful exploitation results in full system compromise, allowing attackers to execute arbitrary system commands, exfiltrate data, or persist within the host environment. This vulnerability is particularly dangerous in multi-tenant environments or systems where untrusted users can define workflow logic. Exploitation requires authenticated access to the application, but no further special privileges beyond the ability to submit expressions for evaluation by the engine.",
"technicalDetails": "The root cause of this vulnerability lies in an inadequate security boundary within the heym expression evaluation engine. Specifically, the DotList map/filter operations and the fallback resolution mechanism do not implement a robust denylist or allowlist for attribute access, failing to sanitize or block access to sensitive dunder attributes (e.g., __subclasses__, __globals__, __builtins__).\nIn Python, dunder attributes provide access to the internal structure of objects and the interpreter. By traversing object hierarchies—often starting from a primitive object available within the expression context—an attacker can reach dangerous modules like os. Because the expression engine evaluates these inputs dynamically without sufficient isolation, it effectively enables access to the full Python runtime environment.\nThe attack flow proceeds as follows: First, the attacker identifies an input vector where the application evaluates workflow expressions using the vulnerable heym component. Second, the attacker crafts a malicious payload that utilizes nested property access, for example, navigating through object '__class__' and '__subclasses__' to find and instantiate or reference the 'os' module.\nA typical payload might look like: 'some_object.__class__.__base__.__subclasses__()[n].__init__.__globals__['os'].system('COMMAND')'. Here, the attacker traverses the MRO (Method Resolution Order) of an object to locate a module that has already imported 'os' or 'subprocess', bypassing the intended limitations of the sandbox environment.\nOnce the attacker successfully resolves the reference to os.system, the expression engine executes the arbitrary command provided by the attacker as a string argument. The command runs with the same security context and operating system privileges as the application process itself, leading to full RCE.\nAffected versions are all versions of heym prior to 0.0.91. This vulnerability exists regardless of network exposure, as it is a logic flaw in code evaluation; therefore, any interface that exposes this expression engine to authenticated users—regardless of their privilege level—is potentially exploitable."
}