Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Chia Min

#49056of 56,330
5.4Total CVSS
Vulnerabilities · 1
PT-2026-51534
5.4
2026-06-23
Unknown · Openharness · CVE-2026-56696
**Name of the Vulnerable Software and Affected Versions** OpenHarness (affected versions not specified) **Description** The `/issue` and `/pr comments` slash commands lack `remote invocable=False` protection. This allows remote channel senders to write attacker-controlled Markdown into project context files, specifically `.openharness/issue.md` and `.openharness/pr comments.md`. This content is subsequently injected into runtime system prompts, which can persistently influence the behavior of local agents. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.