What happened
NVD published on 2026-09-27 (VulnCheck): heym stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91, including MCP API keys and webhook auth that leak into logs, proxies and Referer headers via the ?key= query-string form (CVSS 4.9 v3.1).
Why it matters
heym is an AI workflow automation platform whose nodes call LLMs, MCP servers, and webhooks on behalf of users; plaintext MCP API keys and webhook credentials can be harvested by any read-scoped user and replayed to drive the platform's AI workflows as the owner, undermining agent identity and tool authorization.
Attack vector
Multiple capability secrets are stored and returned in plaintext: webhook header-auth values (GET /api/workflows/{id}, execution history), MCP API keys (plaintext column, accepted via ?key= query string leaking into logs/referrers), portal session tokens (plaintext equality, 168h TTL), execution JWTs (re-listed via /execution-tokens), Discord interaction tokens, and global variables. Anyone who can read them can impersonate the secret owner.
Affected systems
heymrun/heym < 0.0.91 (pkg:pypi/heym)
Mitigation
Upgrade to heym 0.0.91. Advisory: https://github.com/heymrun/heym/security/advisories/GHSA-6x65-w7q7-wg93