Unknown · Openharness Ohmo Gateway · CVE-2026-56695
**Name of the Vulnerable Software and Affected Versions**
OpenHarness ohmo gateway (affected versions not specified)
**Description**
The `/resume` and `/summary` slash commands in the gateway default the `remote invocable` property to True. This allows admitted remote senders to enumerate and load arbitrary session snapshots by ID. An attacker can use this to access victim snapshots through shared gateway channels, potentially exposing private prompts, credentials, tool output, and file paths.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.