PT-2026-63529 · Openyak · Openyak

CVE-2026-46409

·

Published

2026-07-20

·

Updated

2026-08-11

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenYak versions prior to 1.1.3
Description The desktop backend binds an HTTP API to 127.0.0.1:<random port> (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and utilizes a wildcard CORS (Cross-Origin Resource Sharing) policy. This allows any webpage visited by a user to issue cross-origin requests to the local server, bypassing OS-level network isolation. This can lead to remote code execution (RCE) on the host via the build agent when permission presets.bash is set to true, as well as service shutdown and exfiltration of account PII (Personally Identifiable Information) and chat history, requiring no user interaction beyond visiting a malicious page.
Recommendations Update to version 1.1.3.

Exploit

Fix

RCE

Origin Validation Error

Code Injection

CSRF

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-46409
GHSA-CCXP-Q2W5-27JW

Affected Products

Openyak