Sceawere

Vulnerability Detail

CVE-2026-101049UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Heym Slack Signature Verification Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
15h ago
Vendor
heymrun
Product
heym
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-27T17:16:55.967Z",
  "pubdate": "2026-09-27T17:16:55.967Z",
  "executiveSummary": "A critical security flaw in Heym versions prior to 0.0.53 allows remote, unauthenticated attackers to bypass Slack request signature verification. This vulnerability arises when trigger nodes are configured without associated credential IDs or contain empty signing secrets, effectively disabling the cryptographic integrity checks required to validate incoming payloads.\nBy sending forged Slack event requests to publicly accessible webhook URLs, an attacker can masquerade as a legitimate Slack integration. This unauthorized interaction enables the attacker to trigger automated workflows within the Heym environment using the privileges and credentials of the workspace owner.\nThe risk is severe as it allows for unauthorized code execution or workflow orchestration without prior authentication. Successful exploitation requires knowledge of the target webhook endpoint but does not require existing access to the Heym platform or Slack infrastructure. Organizations relying on Heym for workflow automation are exposed to potential data exfiltration or unauthorized system actions until the software is updated.",
  "technicalDetails": "The vulnerability exists within the Heym webhook handling logic responsible for validating incoming HTTP requests from Slack. Slack employs a signature-based mechanism using the 'X-Slack-Signature' header and a shared secret to ensure that incoming events originate from a trusted source. The vulnerability is rooted in an insecure conditional check within the verification routine.\nWhen a trigger node in Heym is initialized, the application attempts to verify the signature if a signing secret is present. However, the implementation fails to enforce mandatory validation; if the trigger node lacks a defined credential ID or the configured signing secret is empty (or null), the validation logic defaults to a bypass state rather than rejecting the request. This flaw effectively permits any incoming request to be treated as legitimate if the internal integrity check is bypassed due to these specific configuration gaps.\nThe attack flow proceeds as follows: An attacker identifies a publicly exposed Heym webhook URL associated with a target workspace. The attacker constructs a malicious payload mimicking a standard Slack event (e.g., a URL verification request or a specific interaction event). Because the vulnerable Heym instance fails to perform cryptographic verification when the signing secret is missing or null, the application accepts the forged HTTP request. Upon processing, the Heym backend treats the request as authenticated, allowing the attacker to execute any downstream workflow or task linked to that specific trigger node.\nThe scope of this vulnerability encompasses all Heym versions released prior to 0.0.53. The exploitation is remote, does not require user interaction from the victim, and circumvents the necessity for valid Slack-provided cryptographic tokens. Post-exploitation, the attacker gains the ability to execute workflows with the permissions of the account owner, potentially resulting in unauthorized modifications, sensitive data access, or the manipulation of downstream services connected to the Heym platform. The lack of strict verification logic serves as the primary technical failure, as the system implicitly trusts any payload delivered to a webhook endpoint that has not been explicitly secured with a valid signing secret."
}
CVE-2026-101049: Heym Slack Signature Verification Bypass (MEDIUM Severity, CVSS: 6.5) | Sceawere