top of page
perceptive_background_267k.jpg

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute ar…

Published:

29 April 2026 at 22:00:00

Alert date:

30 April 2026 at 23:01:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

HKUDS OpenHarness contains a critical remote code execution vulnerability in the /bridge slash command. The vulnerability allows remote senders accepted by configuration to execute arbitrary operating system commands through the /bridge spawn command. Attackers can provide malicious command text that gets forwarded to the bridge session manager and executed via the shared shell subprocess helper. This allows attackers to spawn shell sessions as the OpenHarness process user, potentially accessing local files, credentials, workspace state, and repository contents. The vulnerability has been addressed through patches available on GitHub.

Technical details

Mitigation steps:

Affected products:

HKUDS OpenHarness

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page