CVE-2026-40503
HKUDS OpenHarness, openharness 취약점
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memory directory and access sensitive files accessible to the OpenHarness process without filesystem containment validation.
- 대응 우선순위
- 점검
- CVSS
- 7.1
- EPSS
- 0.41% 백분위 34.1% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.16