CVE-2026-55743
published 2026-06-17CVE-2026-55743: The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to…
PriorityP259critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.39%
32.7th percentile
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tinyhumansai | openhuman | <= 0.54.0 | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
cvelistv5·2026-06-17·CVSS 9.6
CVE-2026-55743 [CRITICAL] CWE-78 OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() blocks the find flags -exec and -ok but not the functionally identical -execdir and -okdir, which also execute an arbitrary command for each matched file; and (2) skip_env_assignments() strips leading inline KEY=value environment-variable assignments before allowlist validation, so a command such as GIT_EXTERNAL_DIFF= git diff is validated as the allowed git diff but, when executed via the shell, runs through g
GHSA
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileg
ghsa_unreviewed·2026-06-17
CVE-2026-55743 [CRITICAL] CWE-78 The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileg
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() blocks the find flags -exec and -ok but not the functionally identical -execdir and -okdir, which also execute an arbitrary command for each matched file; and (2) skip_env_assignments() strips leading inline KEY=value environment-variable assignments before allowlist validation, so a command such as GIT_EXTERNAL_DIFF= git diff is validated as the allowed git diff but, when executed via the shell, runs through git's environment-driven hooks (for example GIT_EXTERNAL_DIFF or GIT_SSH_COMMAND). Becaus
VulDB
tinyhumansai OpenHuman up to 0.54.0 policy.rs is_args_safe os command injection
vuldb·2026-06-17
CVE-2026-55743 [CRITICAL] tinyhumansai OpenHuman up to 0.54.0 policy.rs is_args_safe os command injection
A vulnerability was found in tinyhumansai OpenHuman up to 0.54.0. It has been classified as critical. This issue affects the function is_args_safe of the file src/openhuman/security/policy.rs. This manipulation causes os command injection.
This vulnerability appears as CVE-2026-55743. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published