Security Advisory

CVE-2026-40503

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-16 00:08:09
Last updated 2026-04-16 13:42:38
Assigner VulnCheck
State PUBLISHED

Description

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memory directory and access sensitive files accessible to the OpenHarness process without filesystem containment validation.