---
id: CVE-2026-101049
title: >-
  Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes
  lack credential IDs or have empty signing secrets
summary: >-
  Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes
  lack credential IDs or have empty signing secrets. Remote unauthenticated
  attackers can send forged Slack events to known webhook URLs to trigger
  workflows wi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-287
vendor: heymrun
product: heym
affected:
  - heym < 0.0.53
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T17:16:55.967'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101049'
references:
  - url: >-
      https://github.com/heymrun/heym/commit/341d1012367cd74f85c617e1c98dd49e3fcb5e83
    label: disclosure@vulncheck.com
  - url: 'https://github.com/heymrun/heym/security/advisories/GHSA-pm6h-x3h5-j38h'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/heym-before-0.0.53-slack-webhook-signature-verification-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T16:55:23.213Z'
---

## Overview

Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
