CVE-2026-56696: OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands
OpenHarness /issue and /prcomments slash commands lack remoteinvocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/prcomments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56696?
CVE-2026-56696 has a medium severity score of 5.4.
What are the potential impacts of CVE-2026-56696?
CVE-2026-56696 allows remote attackers to inject malicious Markdown into project context files.
How do I fix CVE-2026-56696?
To fix CVE-2026-56696, implement protection measures to ensure that remote invocable commands are properly restricted.
What software is affected by CVE-2026-56696?
CVE-2026-56696 affects the OpenHarness software platform.
Can CVE-2026-56696 be exploited remotely?
Yes, CVE-2026-56696 can be exploited remotely by attackers with access to remote channels.