PT-2026-63529 · Openyak · Openyak
CVE-2026-46409
·
Published
2026-07-20
·
Updated
2026-08-11
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenYak versions prior to 1.1.3
Description
The desktop backend binds an HTTP API to
127.0.0.1:<random port> (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and utilizes a wildcard CORS (Cross-Origin Resource Sharing) policy. This allows any webpage visited by a user to issue cross-origin requests to the local server, bypassing OS-level network isolation. This can lead to remote code execution (RCE) on the host via the build agent when permission presets.bash is set to true, as well as service shutdown and exfiltration of account PII (Personally Identifiable Information) and chat history, requiring no user interaction beyond visiting a malicious page.Recommendations
Update to version 1.1.3.
Exploit
Fix
RCE
Origin Validation Error
Code Injection
CSRF
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openyak