Path Traversal Vulnerability in OpenHarness by HKUDS
CVE-2026-40503
7.1HIGH
What is CVE-2026-40503?
OpenHarness contains a path traversal vulnerability that allows remote gateway users, having chat access, to exploit the '/memory show' command to read arbitrary files. By manipulating the path input parameter, attackers can navigate beyond the project memory directory and potentially gain unauthorized access to sensitive files that the OpenHarness process can read, without any filesystem containment validation in place.
Affected Version(s)
OpenHarness 0
