CVE-2026-100860
Received Received - Intake

Authentication Bypass in Heym Workflow Redis Node

Vulnerability report for CVE-2026-100860, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None β€” because the credential ID does not exist or the caller is not authorized to use it β€” the node treats the lookup failure as an empty configuration and falls back to defaults, connecting to localhost:6379 with no password and executing the requested operation there. The same fallback occurs when an accessible credential has an empty config or no redis_host value. An authenticated workflow author who supplies a credential ID they do not own, or one that was deleted, therefore obtains a read/write connection to whatever Redis is listening on the backend's loopback interface instead of an error. Impact depends on the deployment: the stock docker-compose.yml ships no Redis, in which case the flaw surfaces as a misleading connection error rather than data exposure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
heym heym to 0.0.105 (exc)
heymrun heym to 0.0.105 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-636 When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Heym before version 0.0.105 involves the Redis node workflow incorrectly handling credential authorization lookups. When a credential ID is invalid, unauthorized, or deleted, the system fails to raise an error and instead defaults to connecting to localhost Redis on port 6379 without a password. This allows an authenticated workflow author to gain unintended access to a local Redis instance if one is running.

Detection Guidance

To detect this vulnerability, check if your Heym instance is running a version before 0.0.105. Inspect the Redis node execution logs for connections to localhost:6379 without authentication. Verify if workflow authors can supply invalid credential IDs without errors.

Impact Analysis

An authenticated attacker could exploit this to connect to and execute operations on a local Redis instance running on the backend's loopback interface. If Redis is not running, the impact may be limited to misleading connection errors. The severity depends on deployment; default Docker setups without Redis reduce exposure.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA if the affected Redis instance stores personal or health data. Unauthorized access to a local Redis instance via localhost:6379 without authentication may lead to data breaches, violating confidentiality requirements under these regulations. However, the actual impact depends on deployment specifics, as the default Docker setup does not include Redis, reducing exposure.

Mitigation Strategies

Upgrade Heym to version 0.0.105 or later. Ensure the Redis node fails securely when credentials are missing or inaccessible by raising a ValueError. Require the redis_host field in credential configurations to prevent defaulting to localhost.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100860. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart