Sceawere

Vulnerability Detail

CVE-2026-105396UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Heym Token Leakage Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
7h ago
Vendor
heymrun
Product
heym
Attack Type
Origin Validation Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T12:17:09.583Z",
  "pubdate": "2026-10-05T12:17:09.583Z",
  "executiveSummary": "A critical token leakage vulnerability exists in Heym versions prior to v0.0.112, stemming from insecure URL generation logic.\nThe vulnerability is classified as an improper trust of HTTP request headers, specifically targeting the build_public_base_url() function.\nBy manipulating 'Origin' or 'X-Forwarded-Host' headers, an unauthenticated remote attacker can influence the construction of absolute URLs generated for Human-in-the-Loop (HITL) review workflows.\nThe primary impact is the exfiltration of sensitive capability tokens, which are transmitted to attacker-controlled infrastructure via poisoned notification links.\nSuccessful exploitation allows an adversary to assume the identity of the system owner, enabling unauthorized submission of HITL decisions.\nThis vulnerability poses a significant risk to the integrity of workflow decisions, as the attacker effectively intercepts the authentication context intended for authorized reviewers.\nNo pre-existing credentials are required to initiate the attack, making it accessible to unauthenticated network-adjacent or remote actors.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and reliance on untrusted HTTP request headers within the build_public_base_url() function in Heym versions prior to v0.0.112.\nThe function incorrectly derives the base URL for critical workflow communication by inspecting the 'Origin' or 'X-Forwarded-Host' headers provided in the incoming HTTP request. These headers are user-controlled input and cannot be considered a reliable source of truth for base URI construction.\nIn a standard HITL workflow, the application generates a unique link for a reviewer to access and adjudicate a task. By spoofing these headers, an attacker forces the application to generate a fully qualified URL pointing to an attacker-controlled domain while maintaining the valid, sensitive capability token as a parameter or path component.\nThe attack flow follows these steps: 1. The attacker triggers an anonymous workflow initiation request, appending malicious 'X-Forwarded-Host' headers containing their controlled domain. 2. The Heym application processes the request and calls build_public_base_url(), which incorporates the forged hostname into the callback links. 3. The system generates a review notification containing the hijacked URL, which is then delivered to an authorized reviewer or internal process. 4. When the recipient interacts with the notification, the browser or system sends the request—including the unique, valid capability token—to the attacker's server. 5. Upon capturing the token, the attacker uses it to authenticate against the legitimate Heym API, successfully impersonating the system owner to authorize or reject workflow tasks.\nThe vulnerability resides in the core URL assembly logic, impacting any feature relying on build_public_base_url() for external communication. Because the system fails to validate these headers against an allow-list or a pre-configured server-side setting, the application remains susceptible to host header injection, leading to severe information disclosure of authentication tokens."
}
CVE-2026-105396: Heym Token Leakage Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere