« Volver al listado

Hkuds

Hkuds Openharness: vulnerabilidades y CVE

Hkuds Openharness tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses10
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-56696Media (5.3)0.37%—23 jun 2026
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can…
CVE-2026-7551Alta (8.7)1.0%—30 abr 2026
HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Attackers can invoke the…
CVE-2026-6823Alta (8.3)0.58%—21 abr 2026
HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote senders to pass admission checks.…
CVE-2026-6819Alta (8.7)0.52%—21 abr 2026
HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access…
CVE-2026-6729Media (5.3)0.34%—20 abr 2026
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared…
CVE-2026-40516Alta (7.8)0.29%—17 abr 2026
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP services by manipulating tool…
CVE-2026-40515Alta (8.7)0.36%—17 abr 2026
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. Attackers can invoke the…
CVE-2026-40503Alta (7.1)0.46%—16 abr 2026
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash…
CVE-2026-40502Alta (8.7)2.1%—16 abr 2026
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between…
CVE-2026-22682Alta (8.4)0.13%—7 abr 2026
OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System3
  2. T1190 Exploit Public-Facing Application3
  3. T1210 Exploitation of Remote Services3
  4. T1059 Command and Scripting Interpreter1
  5. T1068 Exploitation for Privilege Escalation1
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Hkuds