CVE-2026-101049EPSS p20.3%

CVE-2026-101049CVE-2026-101049

Description

Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS0.30% probability of exploitation · percentile 20.3% · 2026-10-05T12:00:23Z
Last modified2026-09-28
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.