---
cve: "CVE-2026-100858"
severity: "HIGH"
cvss: 7.6
epss: "0.3%"
vendor: "heymrun"
kev: false
exploited: false
published: "2026-09-27 02:17:25"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-30T20:17:15+02:00"
---

# CVE-2026-100858

> 7.6 HIGH · 🧪 PoC

## Beschreibung

heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP nodes; the credential API validates only that the URL is non-empty. Any registered user can create a credential pointing at an internal address and execute a workflow, causing the backend to reach loopback, private, link-local, or cloud-metadata endpoints and return the full response body in the node output (non-blind SSRF).

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 1ed1471e978a6a1a526bc796208bb3d38ec54eb3 (Commit)

## Referenzen

- <https://github.com/heymrun/heym/security/advisories/GHSA-39j3-6x3x-8rcr>
- <https://www.vulncheck.com/advisories/heym-before-0.0.109-server-side-request-forgery-via-workflow-nodes>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-100858) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
