Remote Code Execution in OpenYak Desktop due to Inadequate API Security
CVE-2026-46409
9.6CRITICAL
What is CVE-2026-46409?
OpenYak Desktop versions prior to 1.1.3 are vulnerable due to an HTTP API that is bound to a loopback address without adequate security measures. This weakness allows any web page visited by a user to issue cross-origin requests to the local server. By exploiting this vulnerability, an attacker can execute arbitrary shell commands, exfiltrate sensitive user data including chat history and personally identifiable information (PII), and control the OpenYak service without requiring any user interaction beyond visiting a malicious webpage. The issue has been addressed in version 1.1.3, which implements necessary security enhancements.
Affected Version(s)
openyak < 1.1.3
