CVE-2026-45226 Details
Description
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute those workflows under attacker-controlled execution paths, exposing victim workflow outputs and triggering workflow nodes with unintended side effects.
A vulnerability allowing authorization bypass in workflow execution has been identified in Heym versions prior to 0.0.21. This vulnerability allows authenticated users to execute arbitrary workflows by referencing the UUIDs of victim workflows without proper access validation. Attackers can create workflows that include execute nodes or agent subWorkflowIds pointing to these victim UUIDs, thereby loading and executing the workflows along paths controlled by the attacker. This exploitation exposes the outputs of the victim workflows and triggers workflow nodes with unintended consequences.
Users are advised to update to Heym version 0.0.21 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/heymrun/heym/commit/3ae3ef6a7d3609da0e910f9ed6b81e99a1661ac8 | [email protected] | Source CodeVendor |
| https://github.com/heymrun/heym/pull/93 | [email protected] | Issue TrackingVendor |
| https://github.com/heymrun/heym/releases/tag/v0.0.21 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/heym-authorization-bypass-in-workflow-execution | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Heym | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion