CVE-2026-100865 UNKNOWN

CVE-2026-100865

Published: 2026-09-27

Description

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…