Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84207 1 Heymrun 1 Heym 2026-09-02 5.4 Medium
Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach internal services and read responses from the WebSocket Trigger node.