Loading market data...
← Back to CVE feed

CVE-2026-100865

HIGH CVSS 8.8 View on NVD ↗

Description

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Sep 27, 2026 02:17 UTC Modified: Sep 27, 2026 17:16 UTC