Unknown · Openharness · CVE-2026-56696
**Name of the Vulnerable Software and Affected Versions**
OpenHarness (affected versions not specified)
**Description**
The `/issue` and `/pr comments` slash commands lack `remote invocable=False` protection. This allows remote channel senders to write attacker-controlled Markdown into project context files, specifically `.openharness/issue.md` and `.openharness/pr comments.md`. This content is subsequently injected into runtime system prompts, which can persistently influence the behavior of local agents.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.