CVE-2026-56695

MEDIUM

OpenHarness - Cross-Session Disclosure via /resume and /summary Commands

Title source: cna
STIX 2.1

Description

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
HKUDS/OpenHarness < 0.1.9
HKUDS/OpenHarness 92e298852c9b9c8c2266236292073623418c640a
Published Jun 23, 2026
Tracked Since Jun 23, 2026