CVE-2026-40516 is a server-side request forgery (SSRF) vulnerability in OpenHarness versions prior to commit bd4df81 that affects the web_fetch and web_search tools. Attackers can manipulate tool parameters to bypass validation controls and access private HTTP services, including localhost endpoints, RFC1918 addresses, and cloud metadata services on the victim's network. The vulnerability carries a CVSS score of 8.3 (HIGH) with a network-based attack vector requiring no privileges or user interaction. The impact spans confidentiality, integrity, and availability domains, allowing attackers to read response bodies from local development services, administrative panels, and sensitive cloud endpoints accessible from the compromised host. There is no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows minimal community attention with an EPSS score of 0.00047, indicating lower probability of exploitation compared to other published CVEs. Organizations using affected OpenHarness versions should prioritize patching to commit bd4df81 or later to prevent potential reconnaissance and data exfiltration attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-11CPE matchmatch criteria | cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.