Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with… (CVE-2026-100859)
Heym versions before 0.0.106 have a credential exfiltration vulnerability in the POST /api/credentials/test endpoint. This flaw allows collaborators with shared credential access to override the destination URL in the config parameter, causing the server to send decrypted authentication secrets to attacker-controlled endpoints. The vulnerability has a CVSS 3.1 score of 6.5, indicating a high severity impact on confidentiality without affecting integrity or availability.
AI Analysis
Technical Summary
The vulnerability in Heym before version 0.0.106 exists in the POST /api/credentials/test endpoint. Collaborators who have shared credential access can exploit this by overriding the destination URL in the config parameter. This manipulation causes the server to send decrypted authentication secrets to endpoints controlled by the attacker, resulting in credential exfiltration. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) reflects a network attack vector with low attack complexity, requiring privileges, no user interaction, unchanged scope, and high confidentiality impact.
Potential Impact
An attacker with collaborator-level access to shared credentials can exfiltrate the credential owner's secrets by redirecting decrypted authentication data to attacker-controlled endpoints. This compromises the confidentiality of sensitive authentication information but does not affect integrity or availability of the system.
Mitigation Recommendations
No official patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict collaborator access to shared credentials and monitor for suspicious outbound connections from the affected endpoint.
Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with… (CVE-2026-100859)
Description
Heym versions before 0.0.106 have a credential exfiltration vulnerability in the POST /api/credentials/test endpoint. This flaw allows collaborators with shared credential access to override the destination URL in the config parameter, causing the server to send decrypted authentication secrets to attacker-controlled endpoints. The vulnerability has a CVSS 3.1 score of 6.5, indicating a high severity impact on confidentiality without affecting integrity or availability.
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Heym before version 0.0.106 exists in the POST /api/credentials/test endpoint. Collaborators who have shared credential access can exploit this by overriding the destination URL in the config parameter. This manipulation causes the server to send decrypted authentication secrets to endpoints controlled by the attacker, resulting in credential exfiltration. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) reflects a network attack vector with low attack complexity, requiring privileges, no user interaction, unchanged scope, and high confidentiality impact.
Potential Impact
An attacker with collaborator-level access to shared credentials can exfiltrate the credential owner's secrets by redirecting decrypted authentication data to attacker-controlled endpoints. This compromises the confidentiality of sensitive authentication information but does not affect integrity or availability of the system.
Mitigation Recommendations
No official patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict collaborator access to shared credentials and monitor for suspicious outbound connections from the affected endpoint.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-33w4-w3j3-cmvg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100859"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ab89bbcf7a7c54106941eaa
Added to database: 09/27/2026, 04:29:48 UTC
Last enriched: 09/27/2026, 04:35:29 UTC
Last updated: 09/27/2026, 04:35:29 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.