PT-2026-40452 · Heym · Heym
Published
2026-05-12
·
Updated
2026-05-14
·
CVE-2026-45227
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Heym versions prior to 0.0.21
Description
A sandbox escape exists in the custom Python tool executor. Authenticated workflow authors can bypass sandbox restrictions using object-graph introspection primitives. By employing Python introspection techniques, attackers can recover the unrestricted
import function to import blocked modules, such as os and subprocess. This allows access to inherited backend environment variables containing database credentials and encryption keys, enabling the execution of arbitrary host commands as the backend service user.Recommendations
Update to version 0.0.21 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heym