---
cve: "CVE-2026-100865"
severity: "HIGH"
cvss: 8.7
epss: "0.3%"
vendor: "heymrun"
kev: false
exploited: false
published: "2026-09-27 02:17:26"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-06T01:20:48+02:00"
---

# CVE-2026-100865

> 8.7 HIGH · 🧪 PoC

## Beschreibung

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-09-28 13:40:50
- CNA-CVSS: **8.7** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- a8ff9b0ed2a0e87a1b66be56ca0a0ea877e19402 (Commit)
- 341d1012367cd74f85c617e1c98dd49e3fcb5e83 (Commit)

## Referenzen

- <https://github.com/heymrun/heym/security/advisories/GHSA-pm6h-x3h5-j38h>
- <https://github.com/heymrun/heym/commit/341d1012367cd74f85c617e1c98dd49e3fcb5e83>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-100865) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
