CVE 7.1 HIGH

OpenHarness – Cross-Session Disclosure via /resume and /summary Commands_CVE-2026-56695

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.

Basic Information

ID CVE-2026-56695
Source VulnCheck
Published Jun 23, 2026 at 15:36

Affected Product

Vendor HKUDS
Product OpenHarness
Affected Versions HKUDS OpenHarness 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.