CVE-2026-56695

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.
Configurations

No configuration.

History

24 Jun 2026, 15:16

Type Values Removed Values Added
References () https://github.com/HKUDS/OpenHarness/pull/276 - () https://github.com/HKUDS/OpenHarness/pull/276 -

23 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 16:17

Updated : 2026-06-24 15:16


NVD link : CVE-2026-56695

Mitre link : CVE-2026-56695

CVE.ORG link : CVE-2026-56695


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization