PatchSiren cyber security CVE debrief
CVE-2026-105396 heymrun CVE debrief
CVE-2026-105396 is a token leakage vulnerability in the build_public_base_url() function of the Heym application before version 0.0.112. This vulnerability allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers, potentially capturing capability tokens to submit decisions executed with owner credentials.
- Vendor
- heymrun
- Product
- heym
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for the security of Heym applications should assess exposure and prioritize patching to prevent potential token leakage. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify the version of Heym in use and apply patches as necessary to prevent token leakage.
Why it matters
CVE-2026-105396 is a token leakage vulnerability in Heym application before version 0.0.112 that allows unauthenticated attackers to redirect HITL review links and potentially capture capability tokens. Defenders should prioritize verifying the version of Heym in use and applying patches to prevent potential token leakage.
- Potential capture of capability tokens to submit decisions executed with owner credentials
- Redirect of HITL review links by spoofing Origin or X-Forwarded-Host headers
- Verification of Heym version and application of patches to prevent token leakage
Technical summary
The build_public_base_url() function in Heym before version 0.0.112 is vulnerable to token leakage due to improper handling of Origin or X-Forwarded-Host headers. This allows unauthenticated attackers to redirect HITL review links and potentially capture capability tokens. Affected product deployments should be identified and patched to prevent potential token leakage. Defenders should prioritize verifying the version of Heym in use and applying the necessary patches to prevent potential token leakage. The vulnerability impacts systems using Heym before version 0.0.112.
Defensive priority
Defenders should prioritize verifying the version of Heym in use and applying the necessary patches to prevent potential token leakage.
Recommended defensive actions
- Verify the version of Heym in use and apply patches as necessary
- Monitor for suspicious activity related to HITL review links
- Consider implementing additional security measures to protect capability tokens
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source references provide information on the vulnerability, but further verification is needed to determine the full scope of affected systems and potential impact. Affected systems likely include those using Heym before version 0.0.112. Defenders should verify the version of Heym in use and assess exposure to potential token leakage.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105396 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105396
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105396 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105396
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/heymrun/heym/security/advisories/GHSA-6rv3-wh25-7pg5
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/heym-before-0.0.112-hitl-review-token-leak-via-spoofable-origin-header
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.