CVE-2026-40516

Source
https://cve.org/CVERecord?id=CVE-2026-40516
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40516.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40516
Published
2026-04-17T16:02:09.082Z
Modified
2026-07-16T03:31:10.586844285Z
Severity
  • 7.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:L CVSS Calculator
Summary
OpenHarness SSRF via web_fetch and web_search
Details

OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the webfetch and websearch tools that allows attackers to access private and localhost HTTP services by manipulating tool parameters without proper validation of target addresses. Attackers can influence an agent session to invoke these tools against loopback, RFC1918, link-local, or other non-public addresses to read response bodies from local development services, cloud metadata endpoints, admin panels, or other private HTTP services reachable from the victim host.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "bd4df81f634f8c7cddcc3fdf7f561a13dcbf03ae"
                }
            ]
        }
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40516.json",
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/hkuds/openharness

Affected ranges

Type
GIT
Repo
https://github.com/hkuds/openharness
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40516.json"