MEDIUM5.4
GHSA-24cw-228q-3rx9
OpenHarness remote project-context commands allow persistent prompt poisoning
Details
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openharness-ai
Introduced in:
0No fixed version published yet for openharness-ai (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-56696[ADVISORY]
- https://github.com/HKUDS/OpenHarness/pull/272[WEB]
- https://github.com/HKUDS/OpenHarness/commit/27bb93b810e9ea8fa4832eab7152eeb3b4a6bffb[WEB]
- https://github.com/HKUDS/OpenHarness[PACKAGE]
- https://www.vulncheck.com/advisories/openharness-prompt-injection-via-issue-and-pr-comments-slash-commands[WEB]