Executive brief
OpenHarness is an AI automation platform with a gateway component that processes commands from remote users. The /resume and /summary commands were enabled for remote invocation by default, allowing any admitted user on a shared gateway to enumerate and load other users' saved session snapshots. This could expose sensitive data such as private conversation history, credentials, tool outputs, and local file paths that another user had saved in their session.
Technical details
This is a missing authorization vulnerability (CWE-862) in OpenHarness versions <= 0.1.9. The /resume and /summary slash commands were configured with remote_invocable defaulting to True, allowing any authenticated remote user to invoke them over shared gateway channels. The vulnerable handler uses global session snapshot APIs to list and load saved sessions by ID, bypassing the intended sender-scoped session key isolation that the gateway router otherwise enforces. An admitted remote sender can enumerate another user's saved session snapshots and load them into their own runtime context, then use /summary to extract and return the restored transcript content. The fix (merged May 24, 2026) marks /resume and /summary as local-only by default (remote_invocable=False) and requires explicit remote-admin opt-in for deployments that intentionally allow remote administrative session restoration.
Affected products
- OpenHarness openharness-ai <= 0.1.9
Timeline
- 2026-06-23: disclosed
- 2026-05-24: patched: Fix merged in PR #276 on May 24, 2026; advisory published June 23, 2026