


Perceptive Security
SOC/SIEM Consultancy

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute ar…
Published:
29 April 2026 at 22:00:00
Alert date:
30 April 2026 at 23:01:48
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
HKUDS OpenHarness contains a critical remote code execution vulnerability in the /bridge slash command. The vulnerability allows remote senders accepted by configuration to execute arbitrary operating system commands through the /bridge spawn command. Attackers can provide malicious command text that gets forwarded to the bridge session manager and executed via the shared shell subprocess helper. This allows attackers to spawn shell sessions as the OpenHarness process user, potentially accessing local files, credentials, workspace state, and repository contents. The vulnerability has been addressed through patches available on GitHub.
Technical details
Mitigation steps:
Affected products:
HKUDS OpenHarness
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7551
https://github.com/HKUDS/OpenHarness/commit/438e37309778e19060dfe7b172eb142e543c4cd6
https://github.com/HKUDS/OpenHarness/pull/208
https://www.vulncheck.com/advisories/hkuds-openharness-remote-command-execution-via-bridge-slash-command
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
