CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100865

HIGHCVSS 8.8NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflow template containing a malicious condition node — to e

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100865 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100865

HIGHCVSS 8.8NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflow template containing a malicious condition node — to e

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]