
VulDB 🛡@vuldb
A severe vulnerability was disclosed for heymrun Heym (CVE-2026-100865) https://vuldb.com/vuln/410798
0000081
2.3K followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

A severe vulnerability was disclosed for heymrun Heym (CVE-2026-100865) https://vuldb.com/vuln/410798