PT-2026-51534 · Hkuds · Openharness
Chia Min
+1
·
Published
2026-06-23
·
Updated
2026-06-23
·
CVE-2026-56696
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
OpenHarness /issue and /pr comments slash commands lack remote invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openharness