CVE-2026-46409Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is running can issue cross-origin requests to this local server — the browser acts as a proxy into loopback, bypassing OS-level network isolation. Chained, this lets a malicious page execute arbitrary shell commands on the host (RCE) via the build agent with `permission_presets.bash=true`, shut down the service, and exfiltrate chat history and account PII — with no user interaction beyond opening the page. Version 1.1.3 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-306CWE-346CWE-352CWE-942

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-08: 2Technical Details · 2026-08-08: 108-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🖥️ OpenYak vulnerability: visiting a malicious webpage could trigger RCE A critical OpenYak Desktop issue, CVE-2026-46409, has been highlighted in August 8 security coverage. A malicious webpage could potentially interact with the application's local API and execute shell commands on the host. ⚠️ The underlying CVE was published August 7; this is new August 8 coverage. 🔎 Source: TheHackerWire #RCE #OpenYak #CVE #CyberSecurity #AppSec

    Post summary

    The post highlights a newly disclosed CVE‑2026‑46409 that permits remote code execution through a malicious web page interacting with OpenYak's local API, but provides no PoC, exploit, or patch details.

    0000045
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend bind… https://www.cve.org/CVERecord?id=CVE-2026-46409

    Post summary

    The post references CVE-2026-46409 and notes that OpenYak versions prior to 1.1.3 are affected, but it lacks detailed technical information, exploit code, or mitigation guidance.

    00000699
    57.9K followersView on X

Explore more