---
id: CVE-2026-100859
title: >-
  Heym before 0.0.106 contains a credential exfiltration vulnerability in the
  POST /api/credentials/test endpoint that allows collaborators with shared
  credential access to exfiltrate the credential owner's secret
summary: >-
  Heym before 0.0.106 contains a credential exfiltration vulnerability in the
  POST /api/credentials/test endpoint that allows collaborators with shared
  credential access to exfiltrate the credential owner's secret. Attackers can
  override t…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: heymrun
product: heym
affected:
  - heym < 0.0.106
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:25.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100859'
references:
  - url: 'https://github.com/heymrun/heym/security/advisories/GHSA-39qx-wp7x-69rq'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/heym-before-0.0.106-credential-exfiltration-via-url-override
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.580Z'
---

## Overview

Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
