OpenHarness prior to commit dd1d235 contains a path traversal vulnerability in the /memory show slash command that enables remote gateway users with chat access to read arbitrary files from the system. By supplying path traversal sequences in the path input parameter, attackers can escape the project memory directory and access sensitive files accessible to the OpenHarness process, provided the system lacks filesystem containment validation. The vulnerability has a CVSS severity score of 6.5 (Medium) with a network attack vector, low attack complexity, and requirement for low privileges (user authentication). The primary impact is confidentiality, allowing unauthorized disclosure of sensitive information, while integrity and availability remain unaffected. The EPSS score of 0.00018 indicates this vulnerability is less frequently observed in the wild compared to other disclosed CVEs. This vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation. The vulnerability does not appear to be on any hot lists monitored by the security community, and there is no widely available public exploit code. Organizations using OpenHarness should prioritize upgrading to the patched version at commit dd1d235 or later as part of regular maintenance activities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-13CPE matchmatch criteria | cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.