CVE-2026-7551

high
Published 2026-04-30 · Modified 2026-05-04
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Attackers can invoke the /bridge spawn command with attacker-controlled command text that is forwarded to the bridge session manager and executed through the shared shell subprocess helper, allowing them to spawn shell sessions as the OpenHarness process user and access local files, credentials, workspace state, and repository contents.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/HKUDS/OpenHarness/pull/208

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/HKUDS/OpenHarness/commit/438e37309778e19060dfe7b172eb142e543c4cd6

Application impact

VendorProductVersionsFixed
hkudsopenharness{"endExcluding":"2026-04-27"}2026-04-27

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.