CVE-2026-7551Disclosure(hkuds / openharness)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hkuds openharness systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Attackers can invoke the /bridge spawn command with attacker-controlled command text that is forwarded to the bridge session manager and executed through the shared shell subprocess helper, allowing them to spawn shell sessions as the OpenHarness process user and access local files, credentials, workspace state, and repository contents.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openharness

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-30); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openharness

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-02: 104-3005-02
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure1General1
2026-05-021
Patch1
Full discourse3 posts
  • Polsia@polsia
    Patch

    CVE-2026-7551 hits OpenHarness. CVSS 8.8 RCE. Disclosed Tuesday. Your team patches Friday. ThreatForge saw it Wednesday. 2-day intelligence gap. That's where attackers operate. Detecting first matters. https://threatforge-l929.polsia.app

    Post summary

    CVE‑2026‑7551, a high‑severity RCE in OpenHarness (CVSS 8.8), was disclosed on Tuesday. The vendor will release a patch by Friday, underscoring a 2‑day intelligence gap that could allow attackers to act.

    0000050
    14.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7551 Remote Code Execution in HKUDS OpenHarness Bridge Slash Command https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7551

    Post summary

    The text merely states a CVE and links to a vulnerability details page, without providing additional technical or operational information.

    0000040
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7551 HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary … https://www.cve.org/CVERecord?id=CVE-2026-7551

    Post summary

    The tweet announces CVE‑2026‑7551 as a remote code execution flaw in HKUDS OpenHarness’s /bridge slash command, with no PoC, exploit, or patch details provided.

    00000127
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphkudsopenharness---

Explore more