PT-2026-33464 · Unknown · Openharness

Published

2026-04-17

·

Updated

2026-04-19

·

CVE-2026-40516

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenHarness versions prior to commit bd4df81
Description An issue exists in the 'web fetch' and 'web search' tools where target addresses are not properly validated. This allows attackers to manipulate tool parameters to access private and localhost HTTP services. By influencing an agent session, attackers can invoke these tools against loopback, RFC1918, link-local, or other non-public addresses to read response bodies from local development services, cloud metadata endpoints, admin panels, or other private HTTP services reachable from the victim host.
Recommendations Update to the version containing commit bd4df81. As a temporary workaround, restrict the use of the 'web fetch' and 'web search' tools to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-40516

Affected Products

Openharness