OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-100864 (CVSS 8.7)

NVD · officialPublished Sep 27, 2026Risk 37/100

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fallback resolver to access os.system and execute commands as the backend process.

CVSS
8.7
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source