Hkuds

Openharness

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 15:36:24
  • Zuletzt bearbeitet 23.06.2026 17:58:20

OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into ....

  • EPSS 0.23%
  • Veröffentlicht 23.06.2026 15:36:01
  • Zuletzt bearbeitet 24.06.2026 15:16:42

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing ...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 30.04.2026 21:29:17
  • Zuletzt bearbeitet 04.05.2026 18:22:28

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Attackers can invoke the /bridge spawn command with att...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 21.04.2026 20:36:45
  • Zuletzt bearbeitet 07.05.2026 20:29:09

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote senders to pass admission checks. Attackers who can reach the configu...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 21.04.2026 19:41:16
  • Zuletzt bearbeitet 07.05.2026 20:28:15

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can rem...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 20.04.2026 22:16:23
  • Zuletzt bearbeitet 24.04.2026 19:14:28

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 17.04.2026 16:02:09
  • Zuletzt bearbeitet 24.04.2026 20:32:45

OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP services by manipulating tool parameters without proper validation...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 17.04.2026 16:00:07
  • Zuletzt bearbeitet 24.04.2026 20:34:34

OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. Attackers can invoke the built-in grep and glob tools wi...

Exploit
  • EPSS 1.69%
  • Veröffentlicht 16.04.2026 00:08:34
  • Zuletzt bearbeitet 23.04.2026 19:48:16

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe com...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 16.04.2026 00:08:09
  • Zuletzt bearbeitet 23.04.2026 19:39:11

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate th...