Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvmf-7x77-8q82

Опубликовано: 21 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.

EPSS

Процентиль: 10%
0.00197
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.3
nvd
4 месяца назад

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.

EPSS

Процентиль: 10%
0.00197
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-287