CVE-2026-40515: Hkuds Openharness

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. Attackers can invoke the built-in grep and glob tools with sensitive root directories that are not properly evaluated against configured path rules, allowing disclosure of sensitive local file content, key material, configuration files, or directory contents despite configured path restrictions.

Affected products

  • Hkuds Openharness: before 2026-04-11 (fixed in 2026-04-11)

Published 2026-04-17. Last modified 2026-07-14.