Hkuds develops a focused set of infrastructure and application tools, including OpenHarness and LightRAG, that handle configuration management and data processing. The recurring vulnerability patterns center on path traversal, default permissions, authentication bypass, OS command injection, and cryptographic signature verification—weaknesses characteristic of tools that parse user input, manage file system access, or handle authentication logic. Defenders integrating these products should prioritize input validation hardening and access-control review; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hkuds over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7551HIGH HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating sy | Apr 30, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-32847HIGH DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary | May 28, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-40502HIGH OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by expl | Apr 16, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-40516HIGH OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost H | Apr 17, 2026 | 8.3 | 29 | NO | NO |
CVE-2026-6823HIGH HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote | Apr 21, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-6819HIGH HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders b | Apr 21, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-40515HIGH OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permis | Apr 17, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-56695MEDIUM OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by | Jun 23, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-40503MEDIUM OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal se | Apr 16, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-6729HIGH HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other use | Apr 20, 2026 | 7.6 | 24 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hkuds.
Media articles that mention a CVE ID that affects a product developed by Hkuds — matched by CVE ID, not by vendor name.