Command Injection Vulnerability in HarnessV1 Adapter for a Popular AI Tool
CVE-2026-64650

6.3MEDIUM

Key Information:

Vendor

Vercel

Vendor
CVE Published:
20 July 2026

What is CVE-2026-64650?

The HarnessV1 adapter for the ai-sdk/harness-opencode tool has a command injection vulnerability that allows untrusted code to execute arbitrary commands on the host machine. This occurs due to a flaw in how the tool authorizes requests based on command line arguments. In environments prior to version 1.0.29, any process with a command line that includes an allowed helper script can relay requests, enabling malicious dependencies or build scripts to make unauthorized cloud API calls or access sensitive data. Although a patch was implemented in version 1.0.29 to eliminate the insecure authorization method, users are advised to avoid running this tool on untrusted code and limit the exposure of sensitive operations.

Affected Version(s)

@ai-sdk/harness-codex < 1.0.29

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.