CVE-2026-53976Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-06: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-13: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-13: 108-0608-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-53976 - critical 🚨 OpenChamber <1.13.0 - Unauthenticated Arbitrary File Read > OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-53976 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑53976, noting an unauthenticated file‑read via path traversal in OpenChamber before v1.13.0, and links to a ProjectDiscovery library page that likely contains a PoC.

    030225987
    1.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - OpenChamber Arbitrary File Read via Workspace Bypass (CVE-2026-53976) OpenChamber 1.11.7 /api/fs/read, /api/fs/stat, and /api/fs/raw accept allowOutsideWorkspace=true and an absolute path, bypassing the workspace boundary check for unauthenticated path traversal. Attackers can read secrets (JWT keys, SSH keys, env vars) and potentially forge session cookies to bypass auth on password-protected deployments. 👉Affected: OpenChamber 1.11.7

    Post summary

    Announcement of CVE-2026-53976, describing an unauthenticated arbitrary file read vulnerability in OpenChamber caused by a workspace boundary bypass.

    00000120
    282 followersView on X

Explore more