Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-56695

3 месяца назад

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-399c-3gm2-p29v

3 месяца назад

OpenHarness remote resume commands expose other users' saved session snapshots

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56695

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-399c-3gm2-p29v

OpenHarness remote resume commands expose other users' saved session snapshots

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу