openharness-ai
Open-source Python port of Claude Code - an AI-powered CLI coding assistant
Activity
- Latest release
- 4mo ago
- Total releases
- 10
- Cadence
- ~daily
- Last 12 months
- 10
Details
- License
- MIT
- First release
- Apr 05, 2026
| Version | Released | |
|---|---|---|
0.1.9
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.9
patch
Dependencies (25)
+ 17 more |
|
0.1.8
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.8
patch
Dependencies (25)
+ 17 more |
|
0.1.7
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.7
patch
Dependencies (25)
+ 17 more |
|
0.1.6
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.6
patch
Dependencies (25)
+ 17 more |
|
0.1.5
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.5
patch
Dependencies (21)
+ 13 more |
|
0.1.4
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.4
patch
Dependencies (21)
+ 13 more |
|
0.1.3
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.3
patch
Dependencies (21)
+ 13 more |
|
0.1.2
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.2
patch
Dependencies (21)
+ 13 more |
|
0.1.1
patch
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.1
patch
Dependencies (20)
+ 12 more |
|
0.1.0
initial
2 CVEs
CVE-2026-56695
PYSEC-2026-3881
GHSA-399c-3gm2-p29v
Sep 10, 2026
OpenHarness remote resume commands expose other users' saved session snapshots
High
Network
Low
Low
None
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-56696
PYSEC-2026-3880
GHSA-24cw-228q-3rx9
Sep 10, 2026
OpenHarness remote project-context commands allow persistent prompt poisoning
Medium
Network
Low
Low
None
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0
initial
Dependencies (20)
+ 12 more |