🔐 CVE Alert

CVE-2026-22682

HIGH 7.1

OpenHarness Improper Access Control via File Tools

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
1th

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope. Attackers can exploit the path parameter not being passed to the PermissionChecker in read_file, write_file, edit_file, and notebook_edit tools to bypass deny rules and access sensitive files such as configuration files, credentials, and SSH material, or create and overwrite files in restricted host paths in full_auto mode.

CWE CWE-863
Vendor hkuds
Product openharness
Published Apr 7, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for hkuds openharness

Be the first to know when new high vulnerabilities affecting hkuds openharness are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

HKUDS / OpenHarness
0 < 166fcfefb7614dbac51bd061f56542725b0298e9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/HKUDS/OpenHarness/pull/32 github.com: https://github.com/HKUDS/OpenHarness/commit/166fcfefb7614dbac51bd061f56542725b0298e9 vulncheck.com: https://www.vulncheck.com/advisories/openharness-improper-access-control-via-file-tools

Credits

Chia Min Jun Lennon