A AegiFlow
HIGHCVSS 7.1EPSS 0.4%

CVE-2026-56695

OpenHarness remote resume commands expose other users' saved session snapshots

Published
2026-06-23
Modified
2026-09-04
EPSS percentile
33%
Aliases
GHSA-399c-3gm2-p29v
Sources
github-advisory

Summary

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopenharness-ai

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.