Eight Security Flaws Disclosed in Early-Stage Heymrun Heym Automation Tool
Sourced from 1 publication
- •Eight CVEs were published against heymrun Heym, covering code injection, SSRF, improper authorization, missing encryption, privilege mismanagement, and information disclosure
- •The most critical flaw, CVE-2026-100865, enables code injection through the Workflow Condition Evaluator's eval function in versions up to 0.0.52
- •Three distinct server-side request forgery vulnerabilities affect different version ranges, with one residing in the SSRF Guard component meant to prevent such attacks
- •Affected version ranges vary by vulnerability, spanning from 0.0.52 through 0.0.108 depending on the specific flaw
- •VulDB advises upgrading all affected components, though the tool's pre-release version numbering suggests a small install base
Sources
CVE-2026-100865 | heymrun Heym up to 0.0.52 Workflow Condition Evaluator eval re...
Vuldb
CVE-2026-100860 heymrun heym Redis workflow node redis_node.py _get_accessible_c...
Vuldb
CVE-2026-100861 heymrun heym server-side request forgery
Vuldb
CVE-2026-100859 Heymrun Heym test information disclosure
Vuldb
CVE-2026-100864 | heymrun heym up to 0.0.90 Expression Engine privileges managem...
Vuldb
CVE-2026-100858 heymrun heym Workflow Nodes server-side request forgery
Vuldb
CVE-2026-100863 | heymrun Heym up to 0.0.90 SSRF Guard ssrf_guard.py _load_image...
Vuldb
CVE-2026-100862 | heymrun heym up to 0.0.90 missing encryption
Vuldb
Curated from 1 sources. Every summary is reviewed for accuracy, but may still contain errors. We always link to original sources for verification.
Related Stories
About Meridian
Meridian is a free daily newsletter delivering signal-scored news stories with forward-looking analysis every morning. Stories are scored across six criteria (global leverage, capital impact, temporal durability, career relevance, decision utility, and narrative clarity) then assigned to Big Signal, Core, or Quick tiers.
Get Meridian in your inbox
The stories that matter, every morning at 06:00.