GHSA-77h5-29x8-rvxjMediumCVSS 5.0

heym before 0.0.105 fails to apply egress guards to integration services that use credential...

Published
September 27, 2026
Last Modified
September 27, 2026

🔗 CVE IDs covered (1)

📋 Description

heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output.

🔗 References (4)