PYSEC-2026-3881

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/openharness-ai/PYSEC-2026-3881.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3881
Aliases
Published
2026-09-10T09:44:50Z
Modified
2026-09-10T12:15:10Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenHarness remote resume commands expose other users' saved session snapshots
Details

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.

References

Affected packages

PyPI / openharness-ai

Package

Name
openharness-ai
View open source insights on deps.dev
Purl
pkg:pypi/openharness-ai

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.1.9

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/openharness-ai/PYSEC-2026-3881.yaml"