216.73.216.233

CVE-2026-7551

· Published 30/04/2026 22:16 · Modified 30/04/2026 22:16

Labels: CVE-2026-7551 2026-04-30CVE-2026-7551CWE-78[email protected]

Essential information

Published
30/04/2026 22:16
Modified
30/04/2026 22:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Attackers can invoke the /bridge spawn command with attacker-controlled command text that is forwarded to the bridge session manager and executed through the shared shell subprocess helper, allowing them to spawn shell sessions as the OpenHarness process user and access local files, credentials, workspace state, and repository contents.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hkuds / openharness cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:*

References