Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6729

Опубликовано: 20 апр. 2026
Источник: nvd
CVSS3: 6.3
CVSS3: 7.6
EPSS Низкий

Описание

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:*
Версия до 0.1.7 (исключая)

EPSS

Процентиль: 10%
0.00197
Низкий

6.3 Medium

CVSS3

7.6 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.3
github
4 месяца назад

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.

EPSS

Процентиль: 10%
0.00197
Низкий

6.3 Medium

CVSS3

7.6 High

CVSS3

Дефекты

CWE-287