Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 27 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.
Title Heym before 0.0.53 Slack Webhook Signature Verification Bypass
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T16:33:42.372Z

Reserved: 2026-09-27T15:48:49.472Z

Link: CVE-2026-101049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:55.967

Modified: 2026-09-27T17:16:55.967

Link: CVE-2026-101049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:30:17Z

Weaknesses