Product
critical
advisory
HKUDS OpenHarness Remote Code Execution via /bridge Slash Command (CVE-2026-7551)
2 rules 1 TTP 1 CVEHKUDS OpenHarness contains a remote code execution vulnerability (CVE-2026-7551) in the /bridge slash command, allowing remote attackers to execute arbitrary operating system commands by injecting malicious commands via the /bridge spawn command, leading to unauthorized shell access and data exposure.
OpenHarness
rce
vulnerability
injection
2r
1t
1c
critical
advisory
OpenHarness Command Injection Vulnerability (CVE-2026-40502)
2 rules 1 TTP 1 CVEOpenHarness versions prior to commit dd1d235 are vulnerable to command injection, allowing remote gateway users with chat access to execute administrative commands and alter system permissions.
OpenHarness
command-injection
vulnerability
2r
1t
1c
critical
advisory
HKUDS OpenHarness Plugin Management Vulnerability (CVE-2026-6819)
2 rules 3 TTPs 1 CVEHKUDS OpenHarness before PR #156 allows remote attackers with channel layer access to manage plugin lifecycle commands, enabling unauthorized plugin installation and activation.
OpenHarness
cve-2026-6819
plugin-vulnerability
remote-code-execution
2r
3t
1c