CVE-2026-105396: Origin Validation Error in heymrun heym
Description
Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
CVSS v4.0
Score 5.3medium
Affected software
heymrun
heym
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-105396 describes a token leakage vulnerability in heym prior to version 0.0.112. The flaw exists in the build_public_base_url() function, where insufficient validation of Origin or X-Forwarded-Host headers allows unauthenticated attackers to redirect Human-In-The-Loop (HITL) review links. By spoofing these headers, attackers can trigger anonymous workflows that cause reviewer notifications to point to attacker domains. This enables attackers to capture capability tokens, which can then be used to submit decisions with the privileges of the owner.
Potential Impact
The vulnerability allows unauthenticated attackers to redirect review links and capture tokens that grant the ability to submit decisions with owner-level credentials. This could lead to unauthorized actions being performed within the affected system, potentially compromising workflow integrity and security.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor the vendor's official channels for updates and apply any official fixes once available. Until a patch is released, consider restricting or validating incoming Origin and X-Forwarded-Host headers where possible to mitigate exploitation risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-05T10:56:23.833Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac38b252cdf04f656f731f4
Added to database: 10/05/2026, 11:33:57 UTC
Last enriched: 10/05/2026, 11:48:30 UTC
Last updated: 10/05/2026, 18:56:34 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.