CVE-2026-56695 Details
Description
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.
A vulnerability in the OpenHarness Ohmo gateway allows remote senders to access and load arbitrary session snapshots by ID using the /resume and /summary commands. This issue arises because these commands are set to be remotely invocable by default, enabling the enumeration of session snapshots that may contain private prompts, credentials, tool outputs, and file paths through shared gateway channels. The vulnerability affects OpenHarness versions through 0.1.9.
Users can update to OpenHarness version 0.1.10 or later, where this vulnerability has been addressed. Instructions for updating can be found in the OpenHarness documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/OpenHarness/pull/276 | CISA-ADP | Issue TrackingVendor |
| https://github.com/HKUDS/OpenHarness/commit/92e298852c9b9c8c2266236292073623418c640a | [email protected] | Source CodeVendor |
| https://github.com/HKUDS/OpenHarness/pull/276 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/openharness-cross-session-disclosure-via-resume-and-summary-commands | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenHarness | <= 0.1.9 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion