Executive brief
OpenHarness, a tool for managing AI agent workflows, contains a security flaw in how it restricts access to files on the host system. Due to a technical oversight, the software fails to apply security rules to certain file-related commands, allowing an attacker to bypass intended restrictions. This could lead to the theft of sensitive data like SSH keys and credentials, or the unauthorized modification of critical system files.
Technical details
An improper access control vulnerability (CWE-863) exists in OpenHarness due to inconsistent parameter handling between the query runner and the PermissionChecker. While the permission layer expects a 'file_path' parameter to enforce path-based rules, several core tools (read_file, write_file, edit_file, and notebook_edit) use a 'path' parameter, which was not being forwarded for evaluation. A local attacker who can influence agent tool execution can exploit this mismatch to bypass 'deny' rules, enabling arbitrary file reads in default mode and unauthorized file writes/overwrites when the session is in 'full_auto' mode. The vulnerability is addressed in commit 166fcfe by normalizing path extraction and resolving relative paths against the session working directory before permission checks.
Affected products
- HKUDS OpenHarness prior to commit 166fcfe
Timeline
- 2026-04-05: patched: Fix merged in pull request #32
- 2026-04-07: advisory: CVE-2026-22682 published