OVERVIEW: CVE-2026-6729 is a session key derivation vulnerability in HKUDS OpenHarness prior to PR #159 that allows authenticated users to hijack other participants' sessions within shared chats or threads. The flaw stems from an ohmo session key implementation that lacks sender identity verification, enabling attackers to reuse another user's conversation state and manipulate their active tasks through session boundary collisions. SEVERITY: The vulnerability carries a CVSS 3.1 score of 6.3 (MEDIUM) with a network-based attack vector that requires low complexity and valid user authentication. The impact is limited but meaningful, affecting confidentiality, integrity, and availability equally. The attack requires no user interaction and operates within the application's normal scope, making it a credential-dependent threat that could disrupt collaborative workflows and expose sensitive task information. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00034 indicates minimal probability of exploitation compared to other disclosed CVEs. Community attention remains low, with no publicly available exploit code documented.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.7CPE matchmatch criteria | cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.