Beveiligingsadvies

CVE-2026-40503

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-16 00:08:09
Laatst bijgewerkt 2026-07-14 20:00:26
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memory directory and access sensitive files accessible to the OpenHarness process without filesystem containment validation.