{"id":"CVE-2026-100865","summary":"Heym before 0.0.53 Remote Code Execution via eval() Sandbox Escape","details":"Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.","aliases":["CVE-2026-101049","CVE-2026-101050","GHSA-pm6h-x3h5-j38h"],"modified":"2026-09-28T03:55:45.989158278Z","published":"2026-09-27T01:28:53.874Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100865.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100865.json"},{"type":"ADVISORY","url":"https://github.com/heymrun/heym/security/advisories/GHSA-pm6h-x3h5-j38h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100865"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/heym-before-0.0.53-multiple-rce-and-authentication-bypass-vulnerabilities"},{"type":"FIX","url":"https://github.com/heymrun/heym/commit/341d1012367cd74f85c617e1c98dd49e3fcb5e83"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/heymrun/heym","events":[{"introduced":"0"},{"fixed":"a8ff9b0ed2a0e87a1b66be56ca0a0ea877e19402"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.0.53"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v0.0.52","v0.0.51","v0.0.50","v.0.0.49","v0.0.48","v0.0.47","v0.0.46","v0.0.45","v0.0.44","v0.0.43","v0.0.42","v0.0.41","v0.0.40","v0.0.39","v0.0.38","v0.0.37","v0.0.36","v0.0.35","v0.0.34","v0.0.33","v0.0.32","v0.0.31","v0.0.30","v0.0.29","v0.0.27","v0.0.26","v0.0.25","v0.0.24","v0.0.23","v0.0.22","v0.0.21","v0.0.20","v0.0.19","v0.0.18","v0.0.17","v0.0.16","v0.0.15","v0.0.14","v0.0.13","v0.0.12","v0.0.11","v0.0.10","v0.0.9","v0.0.8","v0.0.7","v0.0.6","v0.0.5","v0.0.4","v0.0.3","v0.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100865.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}