{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/plaintext-credentials/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:heym:heym:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-100864"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["heym (\u003c 0.0.91)","Heym (\u003c 0.0.53)"],"_cs_severities":["high"],"_cs_tags":["sandbox-escape","code-execution","expression-engine","web-vulnerability","rce","authentication-bypass","plaintext-credentials"],"_cs_type":"advisory","_cs_vendors":["heym"],"content_html":"\u003cp\u003eThe heym automation and expression engine platform, in versions prior to 0.0.91, contains a critical security flaw involving sandbox escape within its expression processing logic. Specifically, the DotList map/filter functionality and the fallback resolver do not correctly enforce boundary controls on object attribute access. An authenticated attacker can leverage this vulnerability by crafting malicious workflow expressions that utilize Python dunder (double underscore) attributes to traverse the object graph. By accessing these restricted attributes, an attacker can reach the os.system module, ultimately leading to arbitrary code execution within the context of the backend application process. This vulnerability poses a significant risk to organizations using the heym platform for workflow automation, as it allows unauthorized users to transition from limited expression evaluation to full system command execution on the host environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary system commands as the user running the heym backend process. This impact includes unauthorized access to system files, lateral movement within the hosting infrastructure, and the potential for full control over the automation environment. This vulnerability affects all deployments of heym version 0.0.90 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all instances of the heym platform to version 0.0.91 or later to remediate the vulnerable expression engine components.\u003c/li\u003e\n\u003cli\u003eAudit existing workflow expressions for unusual usage of dunder attributes (e.g., \u003cstrong\u003esubclasses\u003c/strong\u003e, \u003cstrong\u003eglobals\u003c/strong\u003e, \u003cstrong\u003edict\u003c/strong\u003e) within the application logs or configuration repository.\u003c/li\u003e\n\u003cli\u003eRestrict access to the workflow creation interface to verified, highly-trusted users only until the patch is deployed, as exploitation requires an authenticated account.\u003c/li\u003e\n\u003cli\u003eMonitor backend process activity for suspicious child processes spawned by the main heym application service.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T03:08:10Z","date_published":"2026-09-27T03:08:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-heym-sandbox-escape/","summary":"The heym expression engine before version 0.0.91 is vulnerable to a sandbox escape via the DotList map/filter and fallback resolver, allowing authenticated users to achieve arbitrary Python code execution.","title":"Sandbox Escape in heym Expression Engine","url":"https://feed.craftedsignal.io/briefs/2026-09-heym-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Plaintext-Credentials","version":"https://jsonfeed.org/version/1.1"}