CVE-2026-100860 | heymrun heym up to 0.0.104 Redis workflow node redis_node.py _get_accessible_credential improper authorization

SecurityVulns

A vulnerability was found in heymrun heym up to 0.0.104. It has been rated as critical. Affected by this vulnerability is the function _get_accessible_credential of the file backend/app/services/node_execution/nodes/redis_node.py of the component Redis workflow node. The manipulation leads to improper authorization.

This vulnerability is referenced as CVE-2026-100860. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More