Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hkuds

First CVE: Apr 8, 2026Active for: 1 yearTotal CVEs: 12
40.5
VTI Score
High

Hkuds develops a focused set of infrastructure and application tools, including OpenHarness and LightRAG, that handle configuration management and data processing. The recurring vulnerability patterns center on path traversal, default permissions, authentication bypass, OS command injection, and cryptographic signature verification—weaknesses characteristic of tools that parse user input, manage file system access, or handle authentication logic. Defenders integrating these products should prioritize input validation hardening and access-control review; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hkuds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2026
3 months ago
Most Recent CVE
Jun 23, 2026
32 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-7551HIGH
HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating sy
Apr 30, 20268.834NONO
CVE-2026-32847HIGH
DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary
May 28, 20267.532NONO
CVE-2026-40502HIGH
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by expl
Apr 16, 20268.832NONO
CVE-2026-40516HIGH
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost H
Apr 17, 20268.329NONO
CVE-2026-6823HIGH
HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote
Apr 21, 20268.228NONO
CVE-2026-6819HIGH
HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders b
Apr 21, 20268.828NONO
CVE-2026-40515HIGH
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permis
Apr 17, 20267.527NONO
CVE-2026-56695MEDIUM
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by
Jun 23, 20266.526NONO
CVE-2026-40503MEDIUM
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal se
Apr 16, 20266.525NONO
CVE-2026-6729HIGH
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other use
Apr 20, 20267.624NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
33%
67%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low7 (58.3%)
High0 (0.0%)
None5 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hkuds.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hkuds — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hkuds's Products

View all 2 CNAs →

Top CWEs