OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memory directory and access sensitive files accessible to the OpenHarness process without filesystem containment validation.
References
| Link | Resource |
|---|---|
| https://github.com/HKUDS/OpenHarness/commit/dd1d235450dd987b20bff01b7bfb02fe8620a0af | Patch |
| https://github.com/HKUDS/OpenHarness/pull/127 | Exploit Issue Tracking |
| https://www.vulncheck.com/advisories/openharness-path-traversal-information-disclosure-via-memory-show | Third Party Advisory |
Configurations
History
23 Apr 2026, 19:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:* | |
| References | () https://github.com/HKUDS/OpenHarness/commit/dd1d235450dd987b20bff01b7bfb02fe8620a0af - Patch | |
| References | () https://github.com/HKUDS/OpenHarness/pull/127 - Exploit, Issue Tracking | |
| References | () https://www.vulncheck.com/advisories/openharness-path-traversal-information-disclosure-via-memory-show - Third Party Advisory | |
| First Time |
Hkuds openharness
Hkuds |
16 Apr 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-16 01:16
Updated : 2026-04-23 19:39
NVD link : CVE-2026-40503
Mitre link : CVE-2026-40503
CVE.ORG link : CVE-2026-40503
JSON object : View
Products Affected
hkuds
- openharness
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
