rootpwn

medium · CVSS v3 4.9 · CVSS v4 6.9 · EPSS 0.00194

CVE-2026-100862

heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0…

Description

heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persisted unsanitized into execution history), MCP API keys (stored as a plaintext column, returned in config/list responses, and accepted via the ?key= query string so they leak into logs, proxies and Referer headers), portal session tokens (stored and validated by plaintext equality with a 168-hour TTL), workflow execution JWTs (stored in full and re-listed by GET .../execution-tokens), Discord interaction tokens (the full interaction body is stored in execution history), and global variables. A user with read access to a workflow, share/team membership, or anyone able to read the database, a backup, or logs can recover these secrets and replay them to execute workflows or act as the secret owner.

Scores

Severity
medium
CVSS v2
6.1
CVSS v3
4.9
CVSS v4
6.9
EPSS
0.00194

← All CVEs