SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84207

MEDIUM · CVSS 5.4 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Heym versions prior to 0.0.98 are vulnerable due to inadequate SSRF egress guards on WebSocket Send and Trigger nodes, enabling authenticated users to access internal services by crafting malicious workflow nodes with arbitrary URLs and headers. This could lead to unauthorized data exposure and potential exploitation of internal resources. Organizations using affected versions should prioritize patching to mitigate the risk of internal service breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84207
Severity
MEDIUM
CVSS
5.4
EPSS
0.20%

Original NVD Description

Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach internal services and read responses from the WebSocket Trigger node.