CVE-2026-40516 Details
Description
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP services by manipulating tool parameters without proper validation of target addresses. Attackers can influence an agent session to invoke these tools against loopback, RFC1918, link-local, or other non-public addresses to read response bodies from local development services, cloud metadata endpoints, admin panels, or other private HTTP services reachable from the victim host.
A server-side request forgery (SSRF) vulnerability has been identified in OpenHarness versions prior to the patch in commit bd4df81. This vulnerability exists within the web_fetch and web_search tools, allowing attackers to access private or localhost HTTP services. The issue arises from inadequate validation of target addresses in tool parameters, enabling exploitation of loopback, RFC1918, link-local, or other non-public addresses. As a result, attackers could read response bodies from local development services, cloud metadata endpoints, admin panels, or other private HTTP services accessible from the victim host.
Users are advised to update to the latest version of OpenHarness, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/OpenHarness/pull/92 | CISA-ADP | ExploitIssue Tracking |
| https://github.com/HKUDS/OpenHarness/commit/bd4df81f634f8c7cddcc3fdf7f561a13dcbf03ae | [email protected] | Patch |
| https://github.com/HKUDS/OpenHarness/pull/92 | [email protected] | ExploitIssue Tracking |
| https://www.vulncheck.com/advisories/openharness-ssrf-via-web-fetch-and-web-search | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hkuds openharness | < 2026-04-11 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |
| Apr 17, 2026 | CVE Modified | CISA-ADP |