Junglewise Threat Intelligence

CVE-2026-55743: tinyhumansai OpenHuman OS command injection via allowlist bypass

CVE-2026-55743 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Executive brief

OpenHuman is a desktop AI agent that automates tasks by interacting with your computer. A security flaw allows a malicious document, email, or website to trick the agent into bypassing its safety rules and executing unauthorized commands on your machine. This could allow an attacker to steal your data, read or delete files, and gain full control over your computer.

Technical details

A command injection vulnerability exists in OpenHuman through version 0.54.0 due to two flaws in 'src/openhuman/security/policy.rs'. First, the 'is_args_safe()' function fails to block the 'find' command flags '-execdir' and '-okdir', which function identically to the blocked '-exec' and '-ok' flags. Second, 'skip_env_assignments()' strips inline environment variables before validation, allowing an attacker to use hooks like 'GIT_EXTERNAL_DIFF' to execute arbitrary code while appearing as a benign 'git' command. An attacker can exploit this via indirect prompt injection (e.g., a malicious email or web page) to achieve remote code execution with the privileges of the desktop user. The issue is fixed in version 0.56.0.

Affected products

  • tinyhumansai OpenHuman through 0.54.0

Timeline

  • 2026-05-26: patched: Fix committed in 60050aa09a870f53ed7e4cd40ed41fd2860329e7
  • 2026-06-17: disclosed: CVE-2026-55743 published

References